A network administrator is migrating an enterprise wireless network from WPA2-Enterprise to WPA3-Enterprise by enabling a transition mode on a Cisco Wireless LAN Controller (WLC). Which two statements accurately describe the protocol mechanisms and operational requirements for this transition deployment? (Select two.)
- Protected Management Frames (PMF) must be set to optional (capable) on the WLAN to allow legacy WPA2 clients to connect alongside WPA3 clients.Answer
- Both WPA2-Enterprise and WPA3-Enterprise utilize the IEEE 802.1X framework and Extensible Authentication Protocol (EAP) for user authentication.Answer
- CWPA3-Enterprise replaces RADIUS authentication with Simultaneous Authentication of Equals (SAE) to establish client identity.
- DFlexConnect local switching mode must be disabled because WPA3-Enterprise requires all client traffic to be centrally switched to process TACACS+ AAA packets.
Answer
Protected Management Frames (PMF) must be set to optional (capable) on the WLAN to allow legacy WPA2 clients to connect alongside WPA3 clients, and both WPA2-Enterprise and WPA3-Enterprise utilize the IEEE 802.1X framework and Extensible Authentication Protocol (EAP) for user authentication.
Both WPA2-Enterprise and WPA3-Enterprise utilize the IEEE 802.1X port-based authentication architecture paired with EAP for centralized client credential verification via RADIUS. Furthermore, because WPA3 mandates Protected Management Frames (802.11w) while WPA2 does not, enabling transition mode on a Wireless LAN Controller requires setting PMF to optional (capable) so both modern WPA3 and legacy WPA2 clients can successfully associate.
Step-by-Step Solution
Key Concept
WPA2/WPA3 Enterprise authentication frameworks and Protected Management Frame (PMF) transition mode settings