Routelearn.net
Course menu

Course 7: Wireless for CCNALesson 2.3 (4 of 4 in this course)49 of 91 in the CCNA series

WPA2/WPA3 configuration on a WLC

Configuring WPA2-PSK, WPA3 and 802.1X/RADIUS security on a WLAN, and how to verify clients connect securely.

Intermediate · 10 min read

WPA2 and WPA3 (Wi-Fi Protected Access 2 and 3) are Wi-Fi security standards that authenticate clients and encrypt wireless traffic. Each can run in Personal mode, where everyone uses one shared passphrase (PSK in WPA2, SAE in WPA3), or in Enterprise mode, where 802.1X and a RADIUS server check each user’s own credentials.

In simple terms: WPA2 and WPA3 decide who may join a Wi-Fi network and scramble the data so outsiders can’t read it. At home everyone shares one password; in a business each person can sign in with their own account.

⚠️ WLC menus follow Cisco AireOS controllers used in CCNA study material. Names vary by release, and nothing here was run in a lab.

A real-life situation

In the lab, the Staff WLAN still uses one shared password. A contractor who left last month still knows it, and so does everyone they told. Changing it means updating every laptop. Management wants staff to sign in with their own accounts, and a separate, simple password for the Guest WLAN.

That is exactly the split this lesson configures: 802.1X with RADIUS for Staff, and a pre-shared key (WPA2 or WPA3) for Guest. For the history (WEP, WPA, TKIP) and the basic ideas, see Wireless security.

What the options are

OptionHow users authenticateEncryptionUse it for
WPA2-Personal (WPA2-PSK)One shared passphraseAES-CCMPSmall sites, guests, simple devices
WPA3-Personal (SAE)One shared passphrase, exchanged with SAEAES-CCMP (GCMP on newer modes)Same uses, more secure
WPA2-Enterprise802.1X: each user, checked by RADIUSAES-CCMPCompany staff
WPA3-Enterprise802.1X, PMF required, optional 192-bit modeAES-CCMP or GCMP-256Staff, high-security sites

Three terms you need first:

  • AKM (Authentication and Key Management): how the keys are agreed. On a WLC you choose PSK, SAE or 802.1X.
  • SAE (Simultaneous Authentication of Equals): WPA3-Personal's exchange. An attacker who records it can't test passwords offline, and each session has its own key (forward secrecy).
  • PMF (Protected Management Frames, 802.11w): signs management frames like deauthentication, so an attacker can't easily kick clients off. Optional in WPA2, required in WPA3.

Why it works this way

With a PSK, everyone knows the same secret. You can't remove one person without changing it for all. With WPA2-PSK an attacker who captures one handshake can also try millions of passwords offline.

802.1X moves the decision to a central RADIUS server. Each user has their own account, so you disable one account when someone leaves. The RADIUS server can also tell the WLC which VLAN or ACL to give that user. Three roles take part:

  • Supplicant: the client (the laptop's 802.1X software).
  • Authenticator: the WLC (for lightweight APs). It passes EAP messages between client and server.
  • Authentication server: RADIUS, such as Cisco ISE, at 10.10.99.50 in the lab.

How it works, step by step

802.1X (Enterprise): EAP over the air, RADIUS on the wire

Step 1 of 6 · Associate to Staff
Laptop
supplicant
WLC1
authenticator
RADIUS
10.10.99.50

1. Associate to Staff · 802.11, via AP1

Open 802.11 authentication and association. The client can't send data yet; only EAP is allowed.

Laptop in RUN state
User:
alice (PEAP)
Cipher:
AES-CCMP
VLAN:
10 · 10.10.10.50
802.1X on a WLAN: EAP between laptop and RADIUS, relayed by the WLC, then the 4-way handshake.

PSK (Personal): straight to the 4-way handshake

With WPA2-PSK there is no RADIUS. Both sides turn the passphrase and SSID into the same PMK (pairwise master key). The 4-way handshake then proves both know it, without sending it, and derives the session keys. If the passphrase is wrong, the handshake fails at message 2 or 3. With WPA3-SAE, an SAE exchange creates the PMK first, then the same 4-way handshake follows.

How to configure it on the WLC

Step 1: add the RADIUS server

SECURITY › AAA › RADIUS › Authentication › New:

FieldValue
Server Index (Priority)1
Server IP Address10.10.99.50
Shared Secret / ConfirmThe same secret configured on the RADIUS server for WLC1
Port Number1812
Server StatusEnabled
Network UserChecked (use this server for wireless clients)

Add the same server under RADIUS › Accounting on port 1813 if you want session records. On the RADIUS server, add WLC1's management address (10.10.99.10) as a network device with the same shared secret.

Step 2: WPA2/WPA3-Enterprise on the Staff WLAN

WLANs › (WLAN ID 1, Staff) › Security:

TabSettingValue
Layer 2Layer 2 SecurityWPA+WPA2
Layer 2Security type / policyWPA2 Policy checked (and WPA3 Policy on releases that offer it)
Layer 2EncryptionAES (CCMP128)
Layer 2Authentication Key Management802.1X
Layer 2PMFOptional for WPA2; Required for WPA3
AAA ServersAuthentication Servers, Server 1IP:10.10.99.50, Port:1812
AdvancedAllow AAA OverrideEnabled if RADIUS should assign VLANs or ACLs per user

Step 3: WPA2-PSK or WPA3-SAE on the Guest WLAN

SettingWPA2-PersonalWPA3-Personal
Layer 2 SecurityWPA+WPA2, WPA2 Policy, AESWPA+WPA2 with WPA3 Policy
Authentication Key ManagementPSKSAE
PSK Format / keyASCII, 8–63 charactersASCII passphrase
PMFDisabled or OptionalRequired

Transition mode (WPA2 and WPA3 together, PSK and SAE both enabled, PMF optional) lets old WPA2-only clients and new WPA3 clients share one SSID while you migrate. Click Apply and Save Configuration when done.

The same on the AireOS CLI

config radius auth add 1 10.10.99.50 1812 ascii MyRadiusSecret config wlan disable 1 config wlan radius_server auth add 1 1 config wlan security wpa enable 1 config wlan security wpa wpa2 enable 1 config wlan security wpa wpa2 ciphers aes enable 1 config wlan security wpa akm 802.1x enable 1 config wlan enable 1

Staff (WLAN 1): RADIUS server index 1, WPA2-AES with 802.1X. The CLI wants a WLAN disabled while you change its security.

config wlan disable 2 config wlan security wpa akm 802.1x disable 2 config wlan security wpa akm psk enable 2 config wlan security wpa akm psk set-key ascii Guest-Passphrase-2026 2 config wlan enable 2 save config

Guest (WLAN 2): WPA2-PSK. Replace the example passphrase with a long, random one.

How to verify it

In the GUI, MONITOR › Clients lists every client; click a MAC address for the details. On the CLI:

Example output · based on Cisco documentation; exact format varies by platform and software version
(Cisco Controller) >show client summary
Number of Clients................................ 2

MAC Address       AP Name          Slot Status      WLAN Auth Protocol          Port Wired Role
----------------- ---------------- ---- ----------- ---- ---- ----------------- ---- ----- -----
3c:22:fb:1a:2b:3c AP1              1    Associated  1    Yes  802.11ax(5 GHz)   13   No    Local
3c:22:fb:4d:5e:6f AP1              0    Associated  2    Yes  802.11n(2.4 GHz)  13   No    Local
Auth Yes means the client passed Layer 2 security. The first client is on WLAN 1 (Staff), the second on WLAN 2 (Guest).
Example output · based on Cisco documentation; exact format varies by platform and software version
(Cisco Controller) >show client detail 3c:22:fb:1a:2b:3c
Client MAC Address............................... 3c:22:fb:1a:2b:3c
Client Username ................................. alice
AP Name.......................................... AP1
Client State..................................... Associated
Wireless LAN Id.................................. 1
Wireless LAN Network Name (SSID)................. Staff
IP Address....................................... 10.10.10.50
Gateway Address.................................. 10.10.10.1
Interface........................................ staff
VLAN............................................. 10
Policy Manager State............................. RUN
...
Policy Type...................................... WPA2
Authentication Key Management.................... 802.1x
Encryption Cipher................................ CCMP-128 (AES)
EAP Type......................................... PEAP
Policy Manager State RUN is the goal: the client is authenticated, has an address and can pass traffic. Policy type, AKM and cipher confirm WPA2-Enterprise with AES. The username came from 802.1X.

What goes wrong and how to troubleshoot it

The Policy Manager State tells you where a client is stuck:

Stuck at / symptomLikely causeWhat to check
8021X_REQD, no RADIUS replyWrong shared secret, WLC not added on the RADIUS server, or UDP 1812 blockedRADIUS server logs; secret on both sides; ACLs between VLAN 99 hosts
8021X_REQD, Access-RejectWrong password, disabled account, or client doesn't trust the server certificateRADIUS logs give the reject reason; client 802.1X settings
Fails during the 4-way handshake (PSK)Wrong passphrase on the clientRe-enter the key; check PSK format (ASCII vs hex)
Old client can't see or joinWPA3-only or PMF required; the client doesn't support itUse transition mode or a separate WPA2 WLAN
DHCP_REQDSecurity passed, but no IP addressDynamic interface VLAN, trunk, DHCP server (see WLC configuration)

Common mistakes

  • Choosing TKIP or "WPA" (version 1). TKIP is deprecated; use AES-CCMP.
  • A short or guessable PSK. WPA2-PSK handshakes can be attacked offline.
  • Adding the AP's address instead of the WLC's on the RADIUS server. With lightweight APs, the WLC sends the RADIUS requests.
  • Turning on WPA3 only and PMF Required while many clients are still WPA2-only.
  • Mixing up 802.1X (the framework) with EAP methods like PEAP or EAP-TLS (how the user proves who they are).

💡 Exam tip: the CCNA asks you to configure a WLAN with WPA2-PSK using the GUI, so know the path: WLANs › WLAN › Security › Layer 2 › WPA+WPA2, WPA2 Policy, AES, AKM PSK, then the key. Also know: Personal = PSK (WPA3 uses SAE), Enterprise = 802.1X with RADIUS, WPA3 requires PMF, and the three 802.1X roles: supplicant, authenticator, authentication server.

Key takeaways

  • Personal mode uses one shared key; Enterprise mode gives each user their own login through RADIUS.
  • WPA3-Personal uses SAE and resists offline password guessing; WPA3 requires PMF.
  • On a WLC: add the RADIUS server, then set Layer 2 security and AKM on the WLAN.
  • The WLC is the 802.1X authenticator; the RADIUS server must know the WLC and its shared secret.
  • A working client reaches Policy Manager State RUN.

Check yourself

Predict · scenario 1

You must configure a WLAN where all users share one passphrase, using WPA2 with AES. Which Authentication Key Management do you select?

Predict · scenario 2

In an 802.1X WLAN with lightweight APs, which device is the authenticator?

Predict · scenario 3

Clients on the Staff WLAN stay in 8021X_REQD and the RADIUS server logs show no requests from WLC1. What is a likely cause?

Predict · scenario 4

Which feature is required by WPA3 but optional in WPA2?

Predict · scenario 5

Why is WPA3-Personal safer than WPA2-Personal against someone who records the connection?

FAQ

What is the difference between WPA2-Personal and WPA2-Enterprise?
Personal uses one pre-shared key (PSK) for everyone. Enterprise uses 802.1X: each user signs in with their own credentials or certificate, checked by a RADIUS server, and each session gets its own keys.
What does WPA3 change?
WPA3-Personal replaces the PSK exchange with SAE, which resists offline password-guessing attacks. WPA3 requires Protected Management Frames (802.11w), and WPA3-Enterprise can use a 192-bit security mode. The 6 GHz band allows only WPA3 or Enhanced Open.
Which UDP ports does RADIUS use?
UDP 1812 for authentication and authorization and UDP 1813 for accounting. Some older servers use 1645 and 1646.