An engineer audits an enterprise wireless deployment configured strictly for WPA3-Enterprise mode. During client connectivity testing, older legacy wireless client devices fail to associate with the SSID, even though their security profiles are configured with valid 802.1X EAP credentials. What mandatory feature of WPA3 security causes these legacy clients to fail association?
- Protected Management Frames (PMF) are strictly required for all associations.Answer
- BRADIUS authentication traffic must be negotiated directly between the client and RADIUS server without access point participation.
- CPre-Shared Keys (PSK) must be negotiated alongside 802.1X credentials during the 4-way handshake.
- DTemporal Key Integrity Protocol (TKIP) is required as the default broadcast cipher suite.
Answer
Protected Management Frames (PMF) are strictly required for all associations.
Under the Wi-Fi Alliance WPA3 standard specification, Protected Management Frames (PMF / IEEE 802.11w) transition from being optional (as in WPA2) to strictly mandatory. Any legacy wireless client device that lacks support for PMF capability negotiation is rejected at association time by a WPA3-configured access point.
Step-by-Step Solution
Key Concept
WPA3 Mandatory Protected Management Frames (PMF / IEEE 802.11w)