11-16-2023 05:51 AM
Hello,
I have a WLAN just for employees and devices that needs internet access only. No internal resources. This WLAN is like a guest WiFi but for employees only for their personal devices. I wanted to change it from WPA2-Personal to WPA2+WPA3-personal. Does anyone see any problem with running in mix mode?
Solved! Go to Solution.
11-16-2023 02:52 PM
@sandeepsingh3200 wrote:
IOT devices
Make the choice. It's it either WPA2 or WPA3. Do not turn both on and "hope" the wireless client can choose correctly. IoT (Internet of Trash) clients will not.
The recommended best practice is to create a totally separate WPA3/6 Ghz SSID.
11-16-2023 10:30 PM - edited 11-16-2023 10:32 PM
One option could be to create the proper Guest SSID using WPA3, and then another one like Guest-legacy for those that do not support it, which could be more than few. There is no way to control guest devices and get to know how many of them do not support WPA3... not all people swap personal devices every year and 3 years old devices could not support it due to the operating system or the hardware.
The best option would be to create the SSID with WPA3-Personal Transition mode with Transition Disable feature enabled, and then monitor how many guests do connect using WPA2. After that you can choose to move to WPA3 or not.
11-16-2023 01:18 PM
Yes, guaranteed there will be problems if there are Windows machines.
Please read this: Cisco Secure Client 5.1.0.136 New Features
Network Access Manager added support for WPA3 802.11 CCMP128 encryption and Protected Management Frames (PMF). However, WPA3 will not work until Microsoft releases a fix that relates to Integrity Group Temporal Key generation. The fix is not available in a production environment, but we anticipate the fix in an upcoming Windows 11 release and Windows 10 22H2 update. While PMF can be used in WPA2, it is required for WPA3 Enterprise. If you have a WPA2 network with PMF required or optional, your connection to Secure Client 5.1.0.136 will fail until the Microsoft fix.
11-16-2023 01:20 PM
These are personal mobile devices,iPhones,iPad,IOT devices
11-16-2023 02:52 PM
@sandeepsingh3200 wrote:
IOT devices
Make the choice. It's it either WPA2 or WPA3. Do not turn both on and "hope" the wireless client can choose correctly. IoT (Internet of Trash) clients will not.
The recommended best practice is to create a totally separate WPA3/6 Ghz SSID.
11-16-2023 10:30 PM - edited 11-16-2023 10:32 PM
One option could be to create the proper Guest SSID using WPA3, and then another one like Guest-legacy for those that do not support it, which could be more than few. There is no way to control guest devices and get to know how many of them do not support WPA3... not all people swap personal devices every year and 3 years old devices could not support it due to the operating system or the hardware.
The best option would be to create the SSID with WPA3-Personal Transition mode with Transition Disable feature enabled, and then monitor how many guests do connect using WPA2. After that you can choose to move to WPA3 or not.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide