Controllerless Networks

 View Only
last person joined: 3 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

UI bug? Can't use internal RADIUS server with WPA3

This thread has been viewed 27 times
  • 1.  UI bug? Can't use internal RADIUS server with WPA3

    Posted May 20, 2022 01:28 PM
    I'm testing WPA3 in a lab with an IAP-315 running Instant 8.10.0. I noticed that when I select WPA2-Enterprise I have the option to use the internal RADIUS server:

    WPA2
    But when I choose WPA3-Enterprise, I'm only allowed to choose external RADIUS servers (InternalServer is not available as an option):

    WPA3
    If I set up the network with WPA2-Enterprise using the internal RADIUS server and then use the CLI to switch to "opmode wpa3-aes-ccm-128" (WPA3-Enterprise), then WPA3-Enterprise appears to work correctly with the internal RADIUS server. So it looks like the internal RADIUS server can be used with WPA3-Enterprise, it's just not possible to configure that in the UI for some reason. Is this expected, or is this a UI bug?

    Thanks!


    ------------------------------
    Jay Seley
    ------------------------------


  • 2.  RE: UI bug? Can't use internal RADIUS server with WPA3

    EMPLOYEE
    Posted Jun 04, 2022 03:30 PM
    I would not use internal database for WPA-Enterprise authentication as it will use PEAP-MSCHAPv2 which is deprecated and should not be used unless you have full control over your clients (supplicants).

    If you ignore that, I would indeed think this may be a UI Bug if it can be configured on CLI but not on UI. It may be on purpose because of the above, but please reach out to Aruba Support and let them find out if this is on purpose, a known, or unknown UI defect.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------