Wireless Access

 View Only
last person joined: 14 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

This thread has been viewed 25 times
  • 1.  Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

    Posted 21 hours ago

    We have two 7200 controllers, a virtual Mobility Conductor running 8.10.0.13, and primarily use AP-515 and AP-325 access points. We've recently purchased Aruba AP-635 access points to replace the AP-325s and plan to enable the 6 GHz band. Our campus environment currently uses WPA2-Enterprise on the 2.4 GHz and 5 GHz bands.

    Initially , I thought WPA3 Transition Mode would apply to the 6 GHz band but after reviewing the requirements and configuration options for WPA3 and the 6 GHz band, I noticed that the 6 GHz band requires WPA3 and is not backward compatible with WPA2 ( no transition mode). This means we cannot configure a single SSID to support both WPA2 and WPA3 across all frequency bands.

    We have several older devices that only support WPA2, and I would prefer not to create separate SSIDs for WPA2 and WPA3 devices. Aruba TAC has confirmed that to use the 6 GHz band, we need to set up an SSID with WPA3 specifically for that band while continuing to use WPA2 for legacy clients on the 2.4 GHz and 5 GHz bands.

    I am not satisfied with this solution. Is there a way to configure a single SSID that supports both the 5 GHz and 6 GHz bands while still providing compatibility for WPA2 devices?



  • 2.  RE: Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

    EMPLOYEE
    Posted 20 hours ago

    WPA3 with transition mode enabled should be providing the backwards compatibility for the WPA2 devices.  The transition mode setting is ignored when that virtual-ap is applied to a 6 GHz radio.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

    EMPLOYEE
    Posted 19 hours ago

    Like Carson said. Configure the SSID for WPA3. Enable both Transition Mode and 6 GHz.

    This should accomplish what you're asking for. A single SSID that allows WPA2 clients in the "legacy" bands of 2.4/5 and also supports WPA3 only in the 6 GHz band. However, at some point, you should consider moving away from transition mode. Like when WPA2 only clients are phased out.




  • 4.  RE: Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

    Posted 15 hours ago

    Take some caution when using WPA3/WPA2 Transition Mode SSIDs.

    I found out later that WPA2 transition mode also enforces MFP (or PMF), i.e. Management frame protection. If you have many diverse client types and ages, this can cause problems for those clients.

    I would advise going with a new SSID and WPA3/WPA2 for newer tested clients... ones that have stable WPA3 and 6Ghz operation.

    Leave WPA2 for the older clients who don't support 6Ghz.




  • 5.  RE: Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

    EMPLOYEE
    Posted 8 hours ago

    This is incorrect. WPA3 Transition Mode (TM) on Aruba APs only enforces PMF in bands where it is required such as 6 GHz. TM does not enforce PMF on 2.4/5 GHz.

    WPA3 TM operation in 2.4/5 GHz:

    • PMF is Optional (MFPR=0/MFPC=1) 

    WPA3 TM operation in 6 GHz:

    • PMF is Required (MFPR=1/MFPC=1)

    This is documented here. https://www.arubanetworks.com/techdocs/aos/wifi-design-deploy/security/modes/




  • 6.  RE: Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

    Posted 6 hours ago

    Thank you schmelzle! So you are saying that the 6 GHz band cannot be configured with WPA2/WPA3 Transition Mode due to the mandatory security features of WPA3 for the 6 GHz band, which are not backward compatible with WPA2. Therefore, we should use one SSID for WPA2 on the 2.4 GHz and 5 GHz bands, and another SSID for WPA3 on the 6 GHz band. Right? Sorry I am confused.




  • 7.  RE: Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

    EMPLOYEE
    Posted 5 hours ago

    No, that's not at all what was shared.  The WLAN configured for WPA3 Transition Mode will provide backward compatibility with WPA2 when operating in the bands (2.4 and 5 GHz) where such is allowed.

    Create one VAP profile that has WPA3 TM enabled.  Apply VAP to AP group.  WLAN will operate as WPA3 TM in 2.4 and 5 GHz.  WLAN will operate as WPA3 in 6 GHz.

    You do not need to create separate SSID or VAP profiles.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 8.  RE: Single SSID for WPA2 and WPA3 on 5 GHz and 6 GHz

    EMPLOYEE
    Posted 5 hours ago

    No, that is not what I'm saying.

    The configuration you're after is WPA3 with Transition Mode.

    When you have WPA3 in Transition Mode, TM will be effective in 2.4/5 GHz only. Effective operation in 6 GHz will result in TM disabled (and this is automatically handled for you, nothing you configure).

    You can use a WPA3 Transition Mode SSID to support WPA2/WPA3 clients in 2.4/5 while supporting WPA3 clients in 6 GHz. One SSID. One configuration. Security parameters are handled automatically depending on the band of operation.