Cisco WLCs Get New WPA2 and WPA3 Options

Phil Morgan • November 25, 2019

Welcome to our November 2019 Blog update where this month I want to focus on changes to the Cisco security settings for WLANs and the new WPA2 and WPA3 options.

Cisco has changed its configuration options on both its AirOS and IOS-XE based controller platforms to include WPA3.

Now, when you select the security options on the latest AirOS controllers (currently 8.10) or IOS-XE controllers (currently 16.12), you get to choose from WPA+WPA2 or WPA2+WPA3. See Figures 1 and 2.

Figure 1: New WPA2 and WPA3 Options – Cisco AirOS Security – Layer 2 Security Setup

Figure 2: Cisco IOS-XE Security – Layer 2 Security Setup

Note: you also get the choice of WPA2 Personal or WPA2 Enterprise, on the AirOS controllers. See Figure 3.

Figure 3: Cisco AirOS Security – Layer 2 Security Type Setup

These options fit more closely with recommendations and vendor design guides. The option to choose Personal or Enterprise is simply selected from a drop-down.

Finally, you can also select WPA3 and configure options such as OWE and SAE.

(Blog article follow-up planned for December on this).

*Note* Amended as of 11/30/19: my intention was to write on WPA3 SAE and OWE (well, Enhanced Open anyway). However, my good friend mrncciew has written a most excellent series of articles on WPA3 and Enhanced Open. So I’ll redirect you to his links instead:
https://mrncciew.com/2019/11/21/enhanced-open-part-1/
https://mrncciew.com/2019/11/29/wpa3-sae-mode/
https://mrncciew.com/2019/11/29/wpa3-sae-transition-mode/

See you next time!

 

About NC-Expert

NC-Expert is a privately-held California corporation and is well established within the Wireless, Security, and Collaboration industry certification training, courseware development, and consulting markets.
Led by its Founder and CEO, Rie Vainstein, NC-Expert has won numerous private contracts with Fortune level companies around the world. These customers have depended on NC-Expert to train, advise, and mentor their staff.

So remember, if you are looking for the best IT training just call us at (855) 941-2121 or contact us

NC-Expert Blog

By Rie Vainstein February 13, 2025
Critical Component for Your Future In today’s ever-evolving tech landscape, staying ahead of the curve is crucial. IT certifications not only validate your expertise but also help open the doors to better career opportunities and advancement. Whether you’re just getting started, or looking to advance, certifications from industry leaders like Ubiquiti , CWNP , CompTIA , and Cisco can be game-changers for your career. Why IT Certifications Matter IT certifications are a proven way to prove your skills and knowledge to employers. As businesses increasingly rely on technology for daily operations, they need professionals who can navigate the complexities of IT infrastructure, networks, and security. A certification can give you a competitive edge, help you land higher-paying roles, and keep you on the cutting edge of the tech industry.
By Phil Morgan February 11, 2025
The Grim Realities of Transition Mode Summary of a recent experience relating to Transition Mode. I have been quite vocal of my hatred of Transition Mode (for WPA3). We have a solution for this - dual SSIDs: https://wifisecuritywizard.com/general/problems-with-wpa3/ IMHO - Transition Mode is dumb! Turn on WPA3, and for everything that doesn’t support it, create a second SSID for now... while you upgrade everything! I have actually said “it’s 2025 for goodness sake, how many devices do you have that don’t do WPA3?!” Well, the other day, the universe decided to mess with me... Scenario: in one of our smaller offices, we are upgrading to Ubiquiti. I arrive on site, I upgrade the system, 5GHz only WPA3, everything is working great! I do one last check, and one of the users mentions, “Oh, the Brother color laser printer isn’t working.” (It’s a nice little device. Prints really well. Cheap to run.)
By Phil Morgan January 24, 2025
This blog is a write up of what was discussed at our AMA webinar session. (Link provided inline.)
Share by: