A network administrator configures a dual-mode WLAN on a Cisco Wireless LAN Controller (WLC) intended to support both modern WPA3-Personal devices and legacy WPA2-Personal client hardware during a corporate migration. WPA3-capable endpoints connect seamlessly; however, older WPA2-only devices consistently fail during the 802.11 association phase and cannot establish network connectivity. Frame captures reveal that the legacy stations receive association responses containing mandatory Protected Management Frames (PMF/802.11w) requirements. Which WLC configuration modification resolves this association failure for legacy endpoints while continuing to support WPA3-Personal clients?
- Set Management Frame Protection (MFP/PMF) to Optional (Capable) on the WLAN profile, allowing legacy stations without 802.11w support to associate.Cevap
- BEnforce Simultaneous Authentication of Equals (SAE) as the exclusive key management method so WPA2 stations can utilize legacy 4-way handshakes.
- CChange the default unicast encryption cipher suite from AES-CCMP128 to GCMP256 across all WLAN security policy profiles.
- DDisable 802.1X authentication parameters on the RADIUS server profile to allow local EAP fallback for legacy pre-shared key processing.
Cevap
Setting Management Frame Protection (MFP/PMF) to Optional (Capable) on the WLAN profile allows legacy stations without 802.11w support to associate.
The choice stating to set Management Frame Protection (MFP/PMF) to Optional (Capable) is correct because IEEE 802.11w PMF is mandatory in WPA3. When configuring WPA3-Personal Transition Mode to accommodate legacy WPA2 devices, setting PMF to Required prevents legacy clients that lack PMF code or hardware support from completing the 802.11 association process. Changing PMF to Optional enables WPA3 endpoints to use PMF while permitting WPA2 endpoints to connect without it.
Adım Adım Çözüm
Anahtar Kavram
WPA3 Transition Mode and Protected Management Frames (PMF / IEEE 802.11w) compatibility requirements