Wireless Access

 View Only
  • 1.  Management Frame protection

    Posted Oct 17, 2025 06:16 AM

    Hello,

    We are debating whether to make Management Frame Protection mandatory on our WPA2 SSIDs as a security measure. But I am trying to get a sense of the effects this may have. I know that for older clients this can cause issues, but I don't know whether nowadays 'older' means pretty ancient and that devices less than (say) 5 years old should have no issues. I also read that there can be issues with 802.11r when 802.11w is enabled - is that still true? How much of a trade-off would making MFPs required be?

    Note that we are a University so don't have full control over what is connecting to the network, there are a lot of BYOD devices, not to mention the usual mish-mash of IoT devices etc.

    Any advice much appreciated.

    Thanks,

    Guy



    -------------------------------------------


  • 2.  RE: Management Frame protection

    Posted Oct 17, 2025 10:47 AM
    Edited by chulcher Oct 17, 2025 10:47 AM

    Is there a reason you'd look at making this change rather than implementing WPA3  with or without transition mode?

    https://arubanetworking.hpe.com/techdocs/aos/wifi-design-deploy/security/features/pmf/

    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Management Frame protection

    Posted Oct 17, 2025 11:08 AM

    Sorry I gave some false info there – eduroam is already WPA3, and is in transition mode. Our IoT network is mPSK, and guest is WPA3 enhanced open. What we are considering is whether to make PMF required for WPA2 clients as a security measure (I'm assuming in transition mode we can set them to required for WPA2 clients?), or whether that would cause a lot of headaches.

     

    Guy

     






  • 4.  RE: Management Frame protection
    Best Answer

    Posted Oct 17, 2025 11:15 AM

    With WPA3 transition mode already enabled, all you'd do by forcing PMF (not sure that's even an option with WPA3 TM enabled) would be to give yourself a headache.  You're functionally forcing WPA3.

    https://arubanetworking.hpe.com/techdocs/aos/wifi-design-deploy/security/modes/wpa3-enterprise/#workaround



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Management Frame protection

    Posted Oct 20, 2025 09:51 AM

    Ok Carson, thank you. Sounds like we should just leave things as they are

    -------------------------------------------