Course menu

Course 7: Wireless for CCNALesson 4.1 (12 of 15 in this course)67 of 132 in the CCNA series

Wireless security: WEP to WPA3 and EAP

Authentication, encryption and integrity; WEP, WPA, WPA2 and WPA3; PSK, SAE and 802.1X with EAP-TLS, PEAP and EAP-FAST; common attacks.

Intermediate · 12 min read

What you will learn

After this lesson, you can explain the three jobs of wireless security, compare WEP, WPA, WPA2 and WPA3, name the main EAP methods, and match common wireless attacks to their defences.

  • WEP/WPA/WPA2/WPA3
  • TKIP vs AES-CCMP
  • SAE and OWE
  • EAP methods

Wireless security protects a WLAN with three things: authentication (only allowed clients join), encryption (others in range can't read the frames) and message integrity (frames can't be changed undetected). Wi-Fi Protected Access (WPA, WPA2, WPA3) defines how these are done; 802.1X with EAP adds per-user authentication through a RADIUS server.

In simple terms: Anyone nearby can pick up a Wi-Fi signal. Security makes sure only the right people get in, nobody else can read what they send, and nobody can tamper with it on the way.

A real-life situation

A café's Wi-Fi uses one password printed on the menu. Someone at the next table runs a capture tool. On a cable they would need to plug into a switch; on Wi-Fi they only need to be in range. What can they see, and what stops them joining or impersonating the café's network? The answers depend entirely on which security the network uses.

The three jobs

  • Authentication: prove the client is allowed in (and, ideally, that the network is the real one).
  • Encryption (privacy): scramble each frame so only the client and AP can read it.
  • Integrity: add a message integrity check (MIC) so a changed frame is detected and dropped.

From WEP to WPA3

WEPWPAWPA2WPA3
Year1999200320042018
EncryptionRC4, static keyTKIP (RC4, per-packet keys)AES-CCMPAES-CCMP; GCMP-256 in 192-bit mode
IntegrityCRC-32 (weak)Michael MICCBC-MAC (in CCMP)CCMP / GCMP
Personal modeShared WEP keyPSKPSKSAE
Enterprise mode–802.1X802.1X802.1X, optional 192-bit mode
Management frame protectionNoNoOptional (802.11w)Required
StatusBrokenDeprecatedAcceptableRecommended

WEP's short initialisation vector made keys recoverable from captured traffic in minutes. WPA was a firmware upgrade for the same hardware, so it kept RC4 but changed the key for each packet (TKIP). WPA2 moved to AES. WPA3 fixed the weaknesses left in WPA2-Personal and made management frame protection mandatory.

Personal: one shared password

With WPA2-PSK, everyone uses the same passphrase. An attacker who captures one four-way handshake can test millions of guesses offline until one matches, so short passwords fall quickly. And anyone who knows the passphrase and captures a handshake can decrypt that client's traffic.

WPA3-Personal (SAE) replaces the handshake's first step with a password-authenticated key exchange. Each guess needs a live exchange with the AP, so offline guessing doesn't work, and every session gets a fresh key (forward secrecy): knowing the password later doesn't unlock old captures.

Enterprise: 802.1X and EAP

In Enterprise mode every user or device has its own credentials, checked by a RADIUS server. The client (supplicant) and the server talk EAP, relayed by the WLC or AP (authenticator). EAP is a framework; the method decides what is proven:

EAP methodServer proves itself withClient proves itself withNotes
EAP-TLSCertificateCertificateStrongest; needs certificates on every client
PEAPCertificateUsername and password (MSCHAPv2) inside a TLS tunnelMost common; clients should check the server certificate
EAP-TTLSCertificateVarious inner methods inside a TLS tunnelSimilar idea to PEAP
EAP-FASTPAC (protected access credential), optionally certificateUsername and password inside a tunnelCisco-developed, avoids certificates
LEAP–Username and password (MS-CHAP)Old Cisco method, vulnerable: don't use

After EAP succeeds, the RADIUS server sends key material to the WLC, and the four-way handshake creates the session keys exactly as in Personal mode.

Open networks and guests

  • Open: no authentication and no encryption. Anyone nearby can read the traffic.
  • Enhanced Open (OWE): still no password, but each client gets its own encryption key, so neighbours can't read each other's traffic. It doesn't prove who the AP is.
  • Web authentication: a captive portal page for terms, a voucher or a guest login, often on an open or OWE WLAN.

Threats and their defences

ThreatWhat happensDefence
EavesdroppingFrames captured from the airWPA2/WPA3 encryption; OWE on open networks
Offline password crackingA captured PSK handshake is guessed offlineLong passphrases; WPA3-SAE; 802.1X
Rogue APAn unauthorised AP plugged into the wired networkRogue detection on the WLC, port security, 802.1X on switch ports
Evil twinA fake AP with your SSID collects logins802.1X with clients that verify the server certificate; WIPS
Deauthentication attackForged deauth frames knock clients offProtected Management Frames (802.11w), required in WPA3

Why it works this way

Radio has no walls, so Wi-Fi assumes an attacker can hear and send every frame. Each generation answered a practical attack on the last one: WEP's keys could be recovered, so WPA changed keys per packet; RC4 was weak, so WPA2 used AES; PSK handshakes could be cracked offline, so WPA3 introduced SAE.

Common mistakes

  • Choosing "WPA2 with TKIP" for compatibility: TKIP is deprecated and limits speed to 802.11a/g rates.
  • Using PEAP without making clients validate the server certificate, which lets an evil twin collect passwords.
  • Thinking a hidden SSID or MAC filter replaces encryption.

💡 Exam tip: match each WPA version to its encryption: WPA = TKIP, WPA2 = AES-CCMP, WPA3 = SAE for Personal plus mandatory PMF. Know that 802.1X roles are supplicant, authenticator and authentication server.

Key takeaways

✅ Key takeaways
  • Wireless security does authentication, encryption and integrity.
  • WEP is broken and WPA (TKIP) deprecated; use WPA2 (AES-CCMP) or, better, WPA3.
  • WPA3-Personal's SAE stops offline guessing and gives forward secrecy; WPA3 requires PMF.
  • Enterprise mode uses 802.1X/EAP with RADIUS: EAP-TLS (certificates), PEAP and EAP-FAST (passwords in a tunnel).
  • Enhanced Open (OWE) encrypts open networks without a password.

Check yourself

Predict · scenario 1

Which encryption does WPA2 use?

Predict · scenario 2

Which WPA3-Personal feature stops an attacker guessing the password offline from a capture?

Predict · scenario 3

Which EAP method uses certificates on both the server and the client?

Predict · scenario 4

Attackers keep disconnecting clients with forged deauthentication frames. What defends against this?

FAQ

Is hiding the SSID or MAC filtering a security measure?
Not a real one. A hidden SSID still appears in probe and association frames, and MAC addresses are sent in clear text, so they are easy to copy. Use WPA2 or WPA3.
Which EAP method is the most secure?
EAP-TLS, because both the server and every client prove themselves with certificates; there is no password to steal. It needs a PKI to issue client certificates, so PEAP with usernames and passwords is more common.