cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1363
Views
5
Helpful
2
Replies

Decrypting 802.11 traffic in wireshark over web authentication SSID.

Muhammed Adnan
Level 4
Level 4

Hello Experts,

 

How do we decrypt the 802.11 traffic for a SSID configured with CWA?

For WPA-PSK & WEP  there will be options in wireshark, however for web authentication SSID, how would we do that?

Decrypt option for wireless PCAP.png

 

 

1 Accepted Solution

Accepted Solutions

Decrypting the wireless traffic is completely independent of the fact that CWA is used or not. CWA only runs after the wireless link is already established. You have two typical situations here:

  1. The SSID is protected with WPA (1 or 2): You configure the PSK in Wireshark as before.
  2. The SSID is open: Noting to decrypt here as the link is already cleartext.

If you want to look into the CWA authentication-traffic of the client, you are probably out of luck. That is HTTPS and outside a lab-environment, you can't decrypt it.

View solution in original post

2 Replies 2

Decrypting the wireless traffic is completely independent of the fact that CWA is used or not. CWA only runs after the wireless link is already established. You have two typical situations here:

  1. The SSID is protected with WPA (1 or 2): You configure the PSK in Wireshark as before.
  2. The SSID is open: Noting to decrypt here as the link is already cleartext.

If you want to look into the CWA authentication-traffic of the client, you are probably out of luck. That is HTTPS and outside a lab-environment, you can't decrypt it.

Thank you Karsten.

Yes indeed, as explained by you for open SSID regardless of CWA or not, the traffic goes un-encrypted.

Review Cisco Networking products for a $25 gift card