Wireless Access

 View Only
Expand all | Collapse all

WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

This thread has been viewed 56 times
  • 1.  WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 09:11 AM

    Hello Dears,

    We have a strange behavior here.

    We have an SSID that uses 802.1x authentication and WPA3-enterprise encryption.

    We only want the WPA3 encryption type to be used; we use WPA3-aes-ccm-128 with Opmode transition Disabled. WPA2 Clients can connect to WPA3-AES-CCM-128 despite Opmode transition being Disabled. 

    We found this document that recommended upgrading to version 8.11.2.1 or later. We upgraded to 8.12.0.5, but still have the same issue.

    Any ideas what the problem is?

    Thanks for your support.



  • 2.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled
    Best Answer

    Posted Jul 09, 2025 09:34 AM
    Edited by Ahmed suliman Jul 09, 2025 12:37 PM

    If the client is capable of AKM:5, it will be able to connect. WPA3-AES-CCM-128 on 8.11 and newer with TM disabled prevents AKM:1 (SHA-1 over .1X) from being used. The best way to confirm this is via OTA pcap during association to see what AKM is being used during association. If AKM:3 (if 802.11r/FT is enabled) or AKM:5 is used by the client, the client will be able to connect and use WPA3. It could be possible the client is actually capable of the WPA3 security parameters?




  • 3.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 09:41 AM

    Hello schmelzle,

    Thanks for your reply.

    These are the protocols supported by the client.




  • 4.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 09:44 AM

    Thanks for the screenshot. I still advise verifying with OTA pcap what AKM the client is actually associating with. AKM:3 and AKM:5 have been around for a long time. AKM:3 is actually shared between WPA2 and WPA3 for FT since AKM:3 already uses SHA-256. We need a packet capture.




  • 5.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 10:30 AM

    Unfortunately, we can't do the  OTA pcap now.

    But I want to ask what if this is the case {the client advertising AKM:5 or AKM:3}.  We want a way to prevent these clients from connecting.




  • 6.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 10:34 AM

    If you don't want to allow WPA3 Enterprise AKMs (AKM:3/AKM:5) you could try switching to WPA3-Enterprise 192-bit (CNSA).




  • 7.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 10:41 AM

    we are using 802.1x EAP PEAP authentication. WPA3-Enterprise 192-bit (CNSA) will work for use or do we must use EAP-TLS ?




  • 8.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 11:44 AM

    That's correct. WPA3-Enterprise 192-bit (CNSA) requires EAP-TLS.




  • 9.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 11:52 AM

    ok thank you so much for your support.

    one last question :D when i choose  wpa3-aes-ccm-256 is asks me for preshared key on the cleints devices why this happens ?




  • 10.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 11:55 AM

    That happens when the client doesn't support the AKM or ciphers and then falls back to something the client knows. We have seen this years ago with other opmodes at their inceptions but isn't so much a problem anymore. 




  • 11.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 12:19 PM

    So this Snap means that my PC does not support wpa3-aes-gcm-256 encryption?




  • 12.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 12:33 PM

    That's correct. The security parameters for WPA3-Enterprise (GCM-256) Non-CNSA are not widely supported by clients. It's a mode for specific customers and scenarios.




  • 13.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 09, 2025 12:37 PM

    Thank you so much for your support and valuable information.




  • 14.  RE: WPA2-only Capable Client able to connect to wpa3-aes-ccm-128 despite Opmode transition: Disabled

    Posted Jul 10, 2025 07:17 AM

    If you would like WPA2 devices to associated to the same SSID as WPA3 you will need to enable transition mode or Opmode transition enabled.