Wireless Access

 View Only
  • 1.  Enhanced Open issues

    Posted Jul 23, 2025 05:12 PM

    Having an issue when using enhanced open, specifically on an iPhone 15 Pro using iOS 18.5. The error being returned by the device is 'incorrect password' when the SSID is selected instead of redirecting to a captive portal. The device works when using a standard open network, and other devices also work when it's configured for enhanced open: iPhone 14 running iOS 18.5 as well, Windows 11 Dell laptop and Pixel 8. Need to be able to offer enhanced open on the SSID as customer has specifically bought 735/755 to use the 6GHz radio.

     AOS version 10.7.1.1. 10.7 is a minimum requirement for the 7xx so limited options for a downgrade. Only upgrade option is 10.7.2.0 which I haven't tried yet. 

     Tests: 
    -WPA3 transition enabled and disabled.

    -WPA3-Personal (SAE) works fine.
    -Management Frame Protection disabled. 
    -20MHz on 5GHz and 6GHz. 2.4GHz will disabled throughout the building due to the amount of APs being deployed.

    -Region is set to GB so shouldn't be an issue with using channel 161 in the upper UNII-3 band. Also a non DFS channel so shouldn't be impacted by radar. iPhone 15 Pro also supports this. 

     In the Central event logs I receive the following when connecting. Which probably isn't actually that useful. 

    image

     

    Full error message description which generally relates to a failed shared key exchange. which in itself is confusing as its not configured that way : Onboarding failed for client fc:31:5d:ea:97:87 in Deauthentication/Disassociation phase to BSSID 98:8f:00:f3:3a:41 on channel 161 of AP hostname 98:8f:00:c7:33:a4. Reason: Response to challenge failed.



  • 2.  RE: Enhanced Open issues

    Posted Jul 23, 2025 06:11 PM

    Hi Adam,

    This shouldn't be happening. Please open a TAC case. 

    P.S. the two knobs for MFP-R and MFP-C have no effect on WPA3/Enhanced Open, they're for WPA2 opmodes only.