Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all
This thread has been viewed 78 times
  • 1.  WPA2 on 6GHz

    Posted May 03, 2023 05:47 PM

    We're struggling to get clients connected successfully connected to our AP-655s on 6GHz, despite seemingly having met all the requirements on the endpoint side (Win11, AX211 chipset, latest drivers).  Surprisingly, all of a sudden a few devices started to work on 6Ghz using WPA2-Enterprise.  From the workstation, netsh wlan show interface  shows WPA2-Enterprise for the authentication method, as does the output from show auth-tracebuf on the controller.  I thought that on 6GHz WPA3 with no backwards compatibility, aka transition mode, was the requirement?  If so, it makes no sense that this device is able to connect on 6GHz.

    Fruthermore, can anyone confirm that 3072+ bits is the required key size for client certs authenticating via EAP-TLS to WPA3-Enterprise networks?



  • 2.  RE: WPA2 on 6GHz

    MVP EXPERT
    Posted May 04, 2023 04:46 AM

    FAIK 6GHz required WPA3 (no backward compatible with WPA2 aka transition mode).
    Not sure about your question about the minimum key size, don't ring a bell to me.
    Did your run latest client drivers and ArubaOS software on your APs/controllers?



    ------------------------------
    Marcel Koedijk | MVP Expert 2023 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
    ------------------------------



  • 3.  RE: WPA2 on 6GHz

    Posted May 04, 2023 08:34 AM

    Not sure about your question about the minimum key size, don't ring a bell to me.

    It came up when we were talking to some engineers at the 6Ghz booth at ATM23.  Clearpass was showing warnings about the encryption key being too small when trying to connect to the 6GHz radio.  They suggested the minimum key requirement is RSA 3072.

    Did your run latest client drivers and ArubaOS software on your APs/controllers?

    Yep, latest AX211 chipset drivers and AOS 8.10.0.6.




  • 4.  RE: WPA2 on 6GHz

    EMPLOYEE
    Posted May 04, 2023 06:18 AM

    You need a separate SSID that supports WPA3 or OWE to run 6Ghz.  There is no "touchless" transition to 6ghz.  Make sure you see the 6ghz light on the access point or type "show AP bss-table" to make sure a 6ghz SSID is being broadcast.  Lastly, make sure your access point is being powered correctly (use IPM).

    Re-reading your post after coffee this time:

    Please setup a separate SSID.  It should not work with anything besides WPA3 or OWE.  This will also make sure we don't have a bug that is allowing you to configure WPA2 with 6ghz and offering you unpredictable results.  We did successfully run WPA3 Enterprise and OWE on 6ghz and even an Airpass (hotspot 2.0) SSID over 6ghz at Atmosphere.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 5.  RE: WPA2 on 6GHz

    Posted May 04, 2023 08:39 AM

    You need a separate SSID that supports WPA3 or OWE to run 6Ghz.  There is no "touchless" transition to 6ghz.  Make sure you see the 6ghz light on the access point or type "show AP bss-table" to make sure a 6ghz SSID is being broadcast.  Lastly, make sure your access point is being powered correctly (use IPM).

    That was another suggestion the engineers at ATM23 gave us, at least as a test; basically process of elimination to figure out why clients weren't connecting at first.  However, after getting back to the office this week, and all of a sudden we have clients connected to the 6GHz network on WPA2 and it makes no sense.  So the main point of my question now is how can this even work?




  • 6.  RE: WPA2 on 6GHz

    EMPLOYEE
    Posted May 04, 2023 08:45 AM

    Type "show dot1x supplicant-info list-all" to make sure those devices are truly using that encryption.



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 7.  RE: WPA2 on 6GHz

    Posted May 04, 2023 05:00 PM

    Thanks for that command! 

    For a 6GHz connected client, that command outputs "/WPA3-AES-CCMP-128     Explicit Mode    EAP-TEAP" for the specific client I'm testing.

    The output from Windows shows that it's WPA2-Enterprise when connected and I triple-checked that the InTune policy for the workstation is set to WPA2 Enterprise.  This makes no sense to me that it should be working if WPA3 is the only protocol that can be used to connect to 6GHz.




  • 8.  RE: WPA2 on 6GHz
    Best Answer

    Posted May 04, 2023 11:20 PM

    Eduroam has explained it well so I'll just quote them:

    There is no explicit "mixed mode", nor is one required: a WPA3-Enterprise network is
    identical to a WPA2-Enterprise network which has configured support for Protected
    Management Frames (PMF). So long as PMFs are only configured as supported, rather than
    required, older WPA2 devices can continue to connect to the network as if it were a normal
    WPA2 network.

    https://www.eduroam.org/wp-content/uploads/eduroam-advice-for-WiFi-Alliance-WPA3.pdf




  • 9.  RE: WPA2 on 6GHz

    Posted May 04, 2023 11:24 PM

    And here's their 6E advice which just refers to the above https://eduroam.org/eduroam-deployment-considerations-on-wi-fi-certified-6e/




  • 10.  RE: WPA2 on 6GHz

    Posted May 10, 2023 03:36 PM

    Thank you for this.  This does seem to be the appropriate answer.




  • 11.  RE: WPA2 on 6GHz

    EMPLOYEE
    Posted May 04, 2023 10:34 AM

    For the key size, WPA3-Enterprise CCM-128 or GCM-256 do not require it.

    WPA3-Enterprise CNSA requires the 3k+ key size with one of the following TLS cipher suites (RFC 6460) to be used in EAP-TLS-

    TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 using p384; or,
    TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 using p384 and RSA > 3k; or,
    TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 using RSA > 3k




    ------------------------------
    Josh
    ------------------------------



  • 12.  RE: WPA2 on 6GHz

    Posted May 08, 2023 07:30 AM

    Hello,

    This is an issue others have been experiencing as well. I wouldn't worry too much, all these 6E bugs still getting worked out. 

    https://techcommunity.microsoft.com/t5/windows-11/windows-shows-wpa2-enterprise-when-it-connect-to-wpa3-enterprise/m-p/3705347