Cannot connect to 802.1X WPA3-enterprise

Shiuan
New here

Cannot connect to 802.1X WPA3-enterprise

Hi all,
 
I am having an issue that Android phone cannot connect to 802.1X WPA3-enterprise.
Android settings display WPA2-enterprise when I configured Meraki as "WPA3-only".
But I can connect to WPA3-enterprise with Cisco C9120AXE AP by the same phone.
 
environment:
APs are CW9166 with version MR 30.5.
802.11w is "Required".
Client is an Android phone A13 which support WPA3-enterprise.
And I can connect to "WPA3-Personal" and "WPA3-enterprise-192 bits" successfully.
2.4G/5G/6GHz radios have the same behavior.
 
Is there any way around this problem?
Does it a compatibility issue with Meraki?
7 Replies 7
alemabrahao
Kind of a big deal
Kind of a big deal

The problem is that in this mode only clients that support 802.11w will be able to connect. Try Transition mode to allow unsupported clients. Otherwise use WPA2.

 

alemabrahao_2-1698146955767.png

 

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

I don't find the "WPA3 Transition Mode" option on the MR30.5. And 802.11w is keeping on Required for WPA3.

Shiuan_1-1698196604913.pngShiuan_2-1698196860677.png

 

alemabrahao
Kind of a big deal
Kind of a big deal

So, like @PhilipDAth saied "Lots of devices can't connect to WPA3 yet.  WPA3 needs at least 12 more months to mature before it can be widely used."

I suggest you use WPA2 for now.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

Lots of devices can't connect to WPA3 yet.  WPA3 needs at least 12 more months to mature before it can be widely used.

Shiuan
New here

Yes, but the specification points out the phone is support WPA3-enterprise secutiry.
And I can get WPA3-enterprise security on the same client by Cisco C9120AX AP with WLC.
So I guess it a compatibility issue or not with Meraki?

PhilipDAth
Kind of a big deal
Kind of a big deal

Windows 11 says it supports WPA3 - but it has a serious bug that causes machines to intermittently disconnect and then not be able to re-connnect.  The fix is scheduled to be released in Aprl 2024.

 

My Samsung phone says it supports WPA3.  I can only keep it connected for about 4 hours.  Then it randomly disconnects, and I have to turn WiFi off and back on again to get it working.

 

 

Lots of things say they are WPA3 compliant.  Doesn't mean they are bug free.

Shiuan
New here

Thanks for the feedback.
But my customer informed that they can get WPA3-enterprise on their side.
I don't how to explain what's different between Meraki and Cisco with WLC.

 

There are no options like "auth key mgmt" can be selected in Meraki.
I don't know the default value is 802.1X-SHA1 or 802.1X-SHA2 when configure as WPA3 only.

 

Shiuan_0-1698220239461.png

 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels