Wireless Access

last person joined: 19 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

wpa3-connectivity - how to tell

This thread has been viewed 17 times
  • 1.  wpa3-connectivity - how to tell

    Posted Jun 07, 2019 06:40 AM

    I've just set up an AP group with 1 AP (303H) on it and a dedicated SSID on our dev ArubaOS 8.5 system and set up key management to be wpa3-enterprise.

    Surprisingly enough my iPhone running iOS 12.3.1 connected to it so I'm assuming that if the client isn't capable of WPA3, it drops down to WPA2 ... but how do you tell?

     

    The ArubaOS GUI doesn't seem to tell you.... or I'm looking in the wrong place ?

     

    Would be good to know just before I start playing with wpa_supplicant 2.8 which does support SAE

     

    Rgds

    Alex



  • 2.  RE: wpa3-connectivity - how to tell

    MVP EXPERT
    Posted Jun 07, 2019 07:06 AM

    Take a look at the AP BSS Table and AP Association and the Flags assigned to the BSSID and Client. Just a note a WPA3 SSID will be in transition mode (WPA3/WPA2) by default unless it is explicitly disabled. 

     

    #show ap bss-table

    Flags: K = 802.11K Enabled; W = 802.11W Enabled; 3 = WPA3 BSS; O = OWE Transition mode OWE BSS; o = OWE Transition mode Open BSS; M = WPA3-SAE mixed mode BSS
    #show ap association
    
    Flags: A: Active, B: Band Steerable, H: Hotspot(802.11u) client, K: 802.11K client, M: Mu beam formee, R: 802.11R client, W: WMM client, w: 802.11w client, V: 802.11v BSS trans capable, P: Punctured preamble, U: HE UL Mu-mimo, O: OWE client, S: SAE client, E: Enterprise client


  • 3.  RE: wpa3-connectivity - how to tell

    EMPLOYEE
    Posted Jun 07, 2019 10:19 AM
    The only difference between WPA2 and WPA3-Enterprise is mandatory MFP. What exactly are you trying to see?


  • 4.  RE: wpa3-connectivity - how to tell

    Posted Jun 07, 2019 10:45 AM

    Guess long and short of it is  if we have  WPA3-enterprise  instead of WPA2-Enterprise associated with a WLAN, what do we look at and where to see if a client connectred system is a WPA2 device or a WPA3 one.

     



  • 5.  RE: wpa3-connectivity - how to tell

    EMPLOYEE
    Posted Jun 07, 2019 10:57 AM
    The only real way is to look for lowercase w flag, but that may not be 100% indicative of WPA3-E


  • 6.  RE: wpa3-connectivity - how to tell

    Posted Jun 07, 2019 10:58 AM

    So are we down to a packet trace then ?



  • 7.  RE: wpa3-connectivity - how to tell

    EMPLOYEE
    Posted Jun 07, 2019 11:00 AM
    I’m still not clear on what you’re trying to see and why.


  • 8.  RE: wpa3-connectivity - how to tell

    EMPLOYEE
    Posted Jun 07, 2019 12:08 PM

    When you type "show ap association client-mac <mac of iphone>" what are the flags?  Is there an "S" flag to indicate that it is an SAE client?

     

     



  • 9.  RE: wpa3-connectivity - how to tell

    Posted Jun 07, 2019 01:09 PM
    I’ll let you know as soon as I’ve set up a WPA3-Personal SSID , be Monday now
    Rgds
    A

    Sent from my iPhone


  • 10.  RE: wpa3-connectivity - how to tell

    EMPLOYEE
    Posted Jun 07, 2019 01:12 PM

    I will save you time.  Do you have a phone that actually supports WPA3?  If not, don't bother... :(



  • 11.  RE: wpa3-connectivity - how to tell

    EMPLOYEE
    Posted Jun 07, 2019 01:16 PM
    Nearly all devices that support Android Q beta support all WPA3 operating modes and OWE.


  • 12.  RE: wpa3-connectivity - how to tell

    EMPLOYEE
    Posted Jun 07, 2019 02:08 PM

    As in NOT iphones.



  • 13.  RE: wpa3-connectivity - how to tell

    Posted Jun 07, 2019 02:09 PM
    So how about wpa-supplicant ?

    Sent from my iPhone


  • 14.  RE: wpa3-connectivity - how to tell

    EMPLOYEE
    Posted Jun 07, 2019 02:15 PM
    Yes, most features are in 2.7 but I’d recommend using 2.8.


  • 15.  RE: wpa3-connectivity - how to tell

    Posted Jun 07, 2019 02:17 PM
    I’ve just built 2.8 on an ubuntu 16.04

    Sent from my iPhone


  • 16.  RE: wpa3-connectivity - how to tell

    Posted Nov 04, 2019 02:51 AM

    What to dio if an Iphone (5) with IOS 13 can not connect to a SSID with WPA3 transistion Mode on?