WPA3 Only Option
Currently, the omada controller offers the option to set the WiFi security mode to "WPA2/WPA3". However, there isn't an option to exclusively use WPA3 security protocol.
Adding a "WPA3 Only" option would be a significant improvement. While the current "WPA2/WPA3" mode ensures backward compatibility by automatically reverting to WPA2 for devices that don't support WPA3, relying solely on WPA3 for security would provide stronger encryption and protection against WPA2 vulnerabilities. By preventing WPA2 devices from connecting, the network's vulnerability to potential compromises posed by WPA2 is eliminated.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
This is crazy that it's not available on enterprise equipment, I have a Deco mesh that's supports it.
I am happy to have WPA2 on old devices or IoT that are on different SSIDs and VLANs to isolate the risk, failback is a terrible idea to be forced.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@jelmervdmeer / @Mjimsas I tried some testing with this by making the change. The Omada interface does show WPA3 only instead of WPA2/WPA3, but it does seem to be rather misleading. I noticed WPA2 kept being announced as a capability ([WPA2-PSK-CCMP-128][RSN-PSK+SAE-CCMP-128][ESS][MFPR][MFPC]). Just to be sure I forced a connection using WPA2 and... it worked. in spite of the controller stating WPA3 only.
If anyone has found the result to be different it's entirely possible of course. This is just what my Controller / AP combination ended up doing.
Controller is an OC200 running 1.37.11. APs are EAP615(EU) (1.5.4) and EAP610(EU) (1.4.4)
On windows I performed
- netsh wlan export profile name="<wifi name>" folder=C:\temp
- Changed <authentication>WPA3SAE</authentication> to <authentication>WPA2PSK</authentication>
As per https://learn.microsoft.com/en-us/windows/win32/nativewifi/wlan-profileschema-authencryption-security-element - netsh wlan add profile filename="C:\temp\<filename>.xml"
- (Re)connect to Wifi network
- Wlan Properties in windows (Wifi -> Click on "Properties").
- Scroll down to Properties - Security Type shows WPA2-Personal
- Copy Link
- Report Inappropriate Content
Information
Helpful: 20
Views: 6244
Replies: 24
