⚠️ WLC menus follow Cisco AireOS controllers used in CCNA study material. Names vary by release, and nothing here was run in a lab.
A real-life situation
In the lab, the Staff WLAN still uses one shared password. A contractor who left last month still knows it, and so does everyone they told. Changing it means updating every laptop. Management wants staff to sign in with their own accounts, and a separate, simple password for the Guest WLAN.
That is exactly the split this lesson configures: 802.1X with RADIUS for Staff, and a pre-shared key (WPA2 or WPA3) for Guest. For the history (WEP, WPA, TKIP) and the basic ideas, see Wireless security.
What the options are
| Option | How users authenticate | Encryption | Use it for |
|---|---|---|---|
| WPA2-Personal (WPA2-PSK) | One shared passphrase | AES-CCMP | Small sites, guests, simple devices |
| WPA3-Personal (SAE) | One shared passphrase, exchanged with SAE | AES-CCMP (GCMP on newer modes) | Same uses, more secure |
| WPA2-Enterprise | 802.1X: each user, checked by RADIUS | AES-CCMP | Company staff |
| WPA3-Enterprise | 802.1X, PMF required, optional 192-bit mode | AES-CCMP or GCMP-256 | Staff, high-security sites |
Three terms you need first:
- AKM (Authentication and Key Management): how the keys are agreed. On a WLC you choose PSK, SAE or 802.1X.
- SAE (Simultaneous Authentication of Equals): WPA3-Personal's exchange. An attacker who records it can't test passwords offline, and each session has its own key (forward secrecy).
- PMF (Protected Management Frames, 802.11w): signs management frames like deauthentication, so an attacker can't easily kick clients off. Optional in WPA2, required in WPA3.
Why it works this way
With a PSK, everyone knows the same secret. You can't remove one person without changing it for all. With WPA2-PSK an attacker who captures one handshake can also try millions of passwords offline.
802.1X moves the decision to a central RADIUS server. Each user has their own account, so you disable one account when someone leaves. The RADIUS server can also tell the WLC which VLAN or ACL to give that user. Three roles take part:
- Supplicant: the client (the laptop's 802.1X software).
- Authenticator: the WLC (for lightweight APs). It passes EAP messages between client and server.
- Authentication server: RADIUS, such as Cisco ISE, at 10.10.99.50 in the lab.
How it works, step by step
802.1X (Enterprise): EAP over the air, RADIUS on the wire
1. Associate to Staff · 802.11, via AP1
Open 802.11 authentication and association. The client can't send data yet; only EAP is allowed.
- User:
- alice (PEAP)
- Cipher:
- AES-CCMP
- VLAN:
- 10 · 10.10.10.50
PSK (Personal): straight to the 4-way handshake
With WPA2-PSK there is no RADIUS. Both sides turn the passphrase and SSID into the same PMK (pairwise master key). The 4-way handshake then proves both know it, without sending it, and derives the session keys. If the passphrase is wrong, the handshake fails at message 2 or 3. With WPA3-SAE, an SAE exchange creates the PMK first, then the same 4-way handshake follows.
How to configure it on the WLC
Step 1: add the RADIUS server
SECURITY › AAA › RADIUS › Authentication › New:
| Field | Value |
|---|---|
| Server Index (Priority) | 1 |
| Server IP Address | 10.10.99.50 |
| Shared Secret / Confirm | The same secret configured on the RADIUS server for WLC1 |
| Port Number | 1812 |
| Server Status | Enabled |
| Network User | Checked (use this server for wireless clients) |
Add the same server under RADIUS › Accounting on port 1813 if you want session records. On the RADIUS server, add WLC1's management address (10.10.99.10) as a network device with the same shared secret.
Step 2: WPA2/WPA3-Enterprise on the Staff WLAN
WLANs › (WLAN ID 1, Staff) › Security:
| Tab | Setting | Value |
|---|---|---|
| Layer 2 | Layer 2 Security | WPA+WPA2 |
| Layer 2 | Security type / policy | WPA2 Policy checked (and WPA3 Policy on releases that offer it) |
| Layer 2 | Encryption | AES (CCMP128) |
| Layer 2 | Authentication Key Management | 802.1X |
| Layer 2 | PMF | Optional for WPA2; Required for WPA3 |
| AAA Servers | Authentication Servers, Server 1 | IP:10.10.99.50, Port:1812 |
| Advanced | Allow AAA Override | Enabled if RADIUS should assign VLANs or ACLs per user |
Step 3: WPA2-PSK or WPA3-SAE on the Guest WLAN
| Setting | WPA2-Personal | WPA3-Personal |
|---|---|---|
| Layer 2 Security | WPA+WPA2, WPA2 Policy, AES | WPA+WPA2 with WPA3 Policy |
| Authentication Key Management | PSK | SAE |
| PSK Format / key | ASCII, 8–63 characters | ASCII passphrase |
| PMF | Disabled or Optional | Required |
Transition mode (WPA2 and WPA3 together, PSK and SAE both enabled, PMF optional) lets old WPA2-only clients and new WPA3 clients share one SSID while you migrate. Click Apply and Save Configuration when done.
The same on the AireOS CLI
config radius auth add 1 10.10.99.50 1812 ascii MyRadiusSecret
config wlan disable 1
config wlan radius_server auth add 1 1
config wlan security wpa enable 1
config wlan security wpa wpa2 enable 1
config wlan security wpa wpa2 ciphers aes enable 1
config wlan security wpa akm 802.1x enable 1
config wlan enable 1Staff (WLAN 1): RADIUS server index 1, WPA2-AES with 802.1X. The CLI wants a WLAN disabled while you change its security.
config wlan disable 2
config wlan security wpa akm 802.1x disable 2
config wlan security wpa akm psk enable 2
config wlan security wpa akm psk set-key ascii Guest-Passphrase-2026 2
config wlan enable 2
save configGuest (WLAN 2): WPA2-PSK. Replace the example passphrase with a long, random one.
How to verify it
In the GUI, MONITOR › Clients lists every client; click a MAC address for the details. On the CLI:
(Cisco Controller) >show client summary Number of Clients................................ 2 MAC Address AP Name Slot Status WLAN Auth Protocol Port Wired Role ----------------- ---------------- ---- ----------- ---- ---- ----------------- ---- ----- ----- 3c:22:fb:1a:2b:3c AP1 1 Associated 1 Yes 802.11ax(5 GHz) 13 No Local 3c:22:fb:4d:5e:6f AP1 0 Associated 2 Yes 802.11n(2.4 GHz) 13 No Local
(Cisco Controller) >show client detail 3c:22:fb:1a:2b:3c Client MAC Address............................... 3c:22:fb:1a:2b:3c Client Username ................................. alice AP Name.......................................... AP1 Client State..................................... Associated Wireless LAN Id.................................. 1 Wireless LAN Network Name (SSID)................. Staff IP Address....................................... 10.10.10.50 Gateway Address.................................. 10.10.10.1 Interface........................................ staff VLAN............................................. 10 Policy Manager State............................. RUN ... Policy Type...................................... WPA2 Authentication Key Management.................... 802.1x Encryption Cipher................................ CCMP-128 (AES) EAP Type......................................... PEAP
What goes wrong and how to troubleshoot it
The Policy Manager State tells you where a client is stuck:
| Stuck at / symptom | Likely cause | What to check |
|---|---|---|
| 8021X_REQD, no RADIUS reply | Wrong shared secret, WLC not added on the RADIUS server, or UDP 1812 blocked | RADIUS server logs; secret on both sides; ACLs between VLAN 99 hosts |
| 8021X_REQD, Access-Reject | Wrong password, disabled account, or client doesn't trust the server certificate | RADIUS logs give the reject reason; client 802.1X settings |
| Fails during the 4-way handshake (PSK) | Wrong passphrase on the client | Re-enter the key; check PSK format (ASCII vs hex) |
| Old client can't see or join | WPA3-only or PMF required; the client doesn't support it | Use transition mode or a separate WPA2 WLAN |
| DHCP_REQD | Security passed, but no IP address | Dynamic interface VLAN, trunk, DHCP server (see WLC configuration) |
Common mistakes
- Choosing TKIP or "WPA" (version 1). TKIP is deprecated; use AES-CCMP.
- A short or guessable PSK. WPA2-PSK handshakes can be attacked offline.
- Adding the AP's address instead of the WLC's on the RADIUS server. With lightweight APs, the WLC sends the RADIUS requests.
- Turning on WPA3 only and PMF Required while many clients are still WPA2-only.
- Mixing up 802.1X (the framework) with EAP methods like PEAP or EAP-TLS (how the user proves who they are).
💡 Exam tip: the CCNA asks you to configure a WLAN with WPA2-PSK using the GUI, so know the path: WLANs › WLAN › Security › Layer 2 › WPA+WPA2, WPA2 Policy, AES, AKM PSK, then the key. Also know: Personal = PSK (WPA3 uses SAE), Enterprise = 802.1X with RADIUS, WPA3 requires PMF, and the three 802.1X roles: supplicant, authenticator, authentication server.
Key takeaways
- Personal mode uses one shared key; Enterprise mode gives each user their own login through RADIUS.
- WPA3-Personal uses SAE and resists offline password guessing; WPA3 requires PMF.
- On a WLC: add the RADIUS server, then set Layer 2 security and AKM on the WLAN.
- The WLC is the 802.1X authenticator; the RADIUS server must know the WLC and its shared secret.
- A working client reaches Policy Manager State RUN.
Check yourself
You must configure a WLAN where all users share one passphrase, using WPA2 with AES. Which Authentication Key Management do you select?
In an 802.1X WLAN with lightweight APs, which device is the authenticator?
Clients on the Staff WLAN stay in 8021X_REQD and the RADIUS server logs show no requests from WLC1. What is a likely cause?
Which feature is required by WPA3 but optional in WPA2?
Why is WPA3-Personal safer than WPA2-Personal against someone who records the connection?