WPA3-ONLY and 802.1X on MR44/MR36

Network_ICT
Here to help

WPA3-ONLY and 802.1X on MR44/MR36

Hi

Windows 10 Clients are still authenticated using WPA2-ENTERPRISE. Why?

Any esperience with WPA3 192 bits?

13 Replies 13
alemabrahao
Kind of a big deal
Kind of a big deal

Because the wireless nic card probably doesn't support WP3.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
alemabrahao
Kind of a big deal
Kind of a big deal

https://www.netspotapp.com/hardware/wpa3-devices/#Are_All_Devices_Compatible_With_WPA3

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Network_ICT
Here to help

Same laptop works with WPA3-Personal.

Once is using 802.1X it shows WPA2-ENTERPRISE.

alemabrahao
Kind of a big deal
Kind of a big deal

Connecting to an SSID with WPA3 does not mean it is supported.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
KarstenI
Kind of a big deal
Kind of a big deal

Windows 10 has problems telling if it is WPA2-Enterprise or WPA3-Enterprise. If you configured the SSID for WPA3-Only, it is WPA3. WPA3 192bit mode opens a can of worms. You don't need it.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Network_ICT
Here to help

You did mention the nic card but if it works with SSID PSK WPA3-ONLY (aka PERSONAL) and it does not work with SSID WPA3-ONLY in 802.1X with custom RADIUS (aka ENTERPRISE).

KarstenI
Kind of a big deal
Kind of a big deal

Personal and Enterprise are completely different technologies. But now you say it doesn't work but before you said it only has the wrong output. What is the actual state?

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Network_ICT
Here to help

Rephrasing: A win 10 laptop works with SSID PSK WPA3-ONLY (aka PERSONAL).

It "does not work" with SSID WPA3-ONLY in 802.1X with custom RADIUS (aka ENTERPRISE) which means once connected it shows: WPA-2 ENTERPRISE.

KarstenI
Kind of a big deal
Kind of a big deal

Windows shows the wrong output, which is a known problem. It works and uses WPA3.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
KarstenI
Kind of a big deal
Kind of a big deal

A little more background: WPA3 Enterprise certifies a specific combination of wireless mechanisms. These mechanisms were already available before WPA3 was published. The Wi-Fi Alliance just gave this very good combination a new name.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Network_ICT
Here to help

And for WPA3 192 bits? it is all up to the client? I've noticed iPhone works, Android not (talking about their quite recent OS).

KarstenI
Kind of a big deal
Kind of a big deal

You will face the most client problems with 192bit mode. And roaming is constrained. 

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Network_ICT
Here to help

Perfect, thank you!

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels