Cisco WLCs Get New WPA2 and WPA3 Options

Welcome to our November 2019 Blog update where this month I want to focus on changes to the Cisco security settings for WLANs and the new WPA2 and WPA3 options.

Cisco has changed its configuration options on both its AirOS and IOS-XE based controller platforms to include WPA3.

Now, when you select the security options on the latest AirOS controllers (currently 8.10) or IOS-XE controllers (currently 16.12), you get to choose from WPA+WPA2 or WPA2+WPA3. See Figures 1 and 2.

Figure 1: New WPA2 and WPA3 Options – Cisco AirOS Security – Layer 2 Security Setup

Figure 2: Cisco IOS-XE Security – Layer 2 Security Setup

Note: you also get the choice of WPA2 Personal or WPA2 Enterprise, on the AirOS controllers. See Figure 3.

Figure 3: Cisco AirOS Security – Layer 2 Security Type Setup

These options fit more closely with recommendations and vendor design guides. The option to choose Personal or Enterprise is simply selected from a drop-down.

Finally, you can also select WPA3 and configure options such as OWE and SAE.

(Blog article follow-up planned for December on this).

*Note* Amended as of 11/30/19: my intention was to write on WPA3 SAE and OWE (well, Enhanced Open anyway). However, my good friend mrncciew has written a most excellent series of articles on WPA3 and Enhanced Open. So I’ll redirect you to his links instead:
https://mrncciew.com/2019/11/21/enhanced-open-part-1/
https://mrncciew.com/2019/11/29/wpa3-sae-mode/
https://mrncciew.com/2019/11/29/wpa3-sae-transition-mode/

See you next time!

 

About NC-Expert

NC-Expert is a privately-held California corporation and is well established within the Wireless, Security, and Collaboration industry certification training, courseware development, and consulting markets.
Led by its Founder and CEO, Rie Vainstein, NC-Expert has won numerous private contracts with Fortune level companies around the world. These customers have depended on NC-Expert to train, advise, and mentor their staff.

So remember, if you are looking for the best IT training just call us at (855) 941-2121 or contact us

NC-Expert Blog

By Rie Morgan August 13, 2026
There is something wonderfully reassuring about seeing a row of green APs on a wireless dashboard: APs connected; radios operational; no obvious alarms; everything green. Excellent! The Wi-Fi must be fine... Except, of course, the users are complaining that Teams calls are breaking up, handheld scanners keep disconnecting, authentication takes forever, and someone in Accounting has discovered that turning Wi-Fi off and back on again temporarily fixes everything. Welcome to one of the more persistent myths in enterprise wireless: if the AP is up, the Wi-Fi must be working. An operational AP tells us something useful... but it tells us surprisingly little about the experience of the clients actually using the network. “Up” is an Infrastructure State When a monitoring platform reports that an AP is up, it usually means the infrastructure can communicate with it. It tells us: - the AP has power - its Ethernet connection is functioning - it may have established its management or CAPWAP connection - its radios are probably operational - it hasn't disappeared into the networking equivalent of a “black hole” ...all good things. But none of those things proves that a client can successfully use an application. Consider what still has to happen after the AP proudly announces its existence. A client must: discover the WLAN associate authenticate obtain the appropriate network configuration reach its default gateway resolve DNS access the required network resources, and maintain sufficient RF performance to exchange data reliably. Depending on the environment, that journey may involve: 802.1X RADIUS DHCP DNS VLANs ACLs firewalls roaming mechanisms upstream switching WAN connectivity cloud services ...and several other systems waiting for their opportunity to make your afternoon more “interesting”. ;-) The AP actually being operational is merely one part of that chain!
By Rie Morgan August 6, 2026
If there's one thing network users love, it's bandwidth. Need faster Wi-Fi? More bandwidth. Application running slowly? More bandwidth. Video buffering? More bandwidth. Someone sneezed near the wireless network? Probably needs more bandwidth. :) As Wi-Fi engineers, we've all heard it. Somewhere along the way, bandwidth became synonymous with performance. But while bandwidth certainly matters, it's only one ingredient in a much larger recipe. In many deployments, increasing available bandwidth produces little improvement and, in some cases, it can actually make things worse! Like many Wi-Fi myths, this one contains just enough truth to be convincing. Let's bust it...
By Rie Morgan July 30, 2026
Every new Wi-Fi generation arrives with a wave of excitement: faster speeds; lower latency; more efficient use of the spectrum; and better handling of dense environments. Wi-Fi 7 is no exception. It brings some genuinely impressive technological advances but, unfortunately, it also brings a familiar myth: "If we upgrade to Wi-Fi 7, all of our wireless problems will disappear." If only wireless engineering were that simple. Wi-Fi 7 is an outstanding technology, but it isn't a magic wand. Poor design, interference, bad client behavior, and unrealistic expectations don't suddenly vanish because the APs have a shiny new logo on the box. Let's bust another myth...