Information about SuiteB-1X and SuiteB-192-1X Support in FlexConnect Mode for WPA2 and WPA3
Support for SuiteB-192-1X and SuiteB-1X Ciphers in FlexConnect Mode
From Cisco IOS XE 17.15.1 onwards, Cisco WLAN FlexConnect mode supports enterprise authentication key management (AKM) — SuiteB-192-1X (AKM 12) and SuiteB-1X (AKM 11). These AKMs are already supported in the Local mode. This section describes the configuration for SuiteB-192-1X and SuiteB-1X in FlexConnect mode, and also the requirements to support Galois Counter Mode Protocol 128 (GCMP-128), GCMP-256, and Counter Cipher Mode with Block Chaining Message Authentication Code Protocol 256 (CCMP-256) ciphers for pairwise transport keys (PTK) and group temporal key (GTK) derivation in FlexConnect Local Authentication mode and FlexConnect Central Authentication mode.
Authentication Types and Ciphers in FlexConnect Mode During PTK and GTK Derivation
-
In WPA2 FlexConnect mode:
-
SUITEB192-1X ciphers are CCMP-256 and GCMP-256.
-
SUITEB-1X cipher is GCMP-128.
-
-
In WPA3 FlexConnect mode:
-
SUITEB192-1X cipher is GCMP-256.
-
SUITEB-1X cipher is GCMP-128.
-
Wi-Fi 7 WPA3 Security Constraints
In Cisco IOS XE 17.15.2, the Wi-Fi 7 standard dictates the following security constraints, which are applicable for Wi-Fi 7 compliant APs:
-
Open authentication as Wi-Fi 7 is not permitted.
-
WPA1 as Wi-Fi 7 is not permitted.
-
WPA2 as Wi-Fi 7 is not permitted.
-
WPA3 is permitted with the following restrictions:
-
SAE(24/25) is permitted with GCMP-256.
-
SAE(8/9) is permitted. (It is beaconed as a Wi-Fi 7 client. This is a deviation from the actual security constraint.)
-
WPA2 with PMF is permitted.
-
802.1x-SHA256 with PMF is permitted.
-
Suite-B-192 with PMF is permitted.
-
![]() Note |
When multi-ciphers (GCMP-128 + GCMP-256) and multi-AKMs (SuiteB + SuiteB-192) are enabled on a WLAN, clients that are compatible with WPA3 security will not support GCMP-128 encryption. Clients supporting GCMP-128 encryption, will not be able to join the GCMP-128 + GCMP-256 cipher with SuiteB and SuiteB-192 AKMs. |