CCNA learning path

A visible SSID is only the beginning.

Work through the settings that turn a WLAN into a usable client connection. This free exercise covers configuration choices and troubleshooting dependencies without requiring a controller.

WPA2 and WPA3: what changes

The Security tab below offers both. They protect the same WLAN, but the personal mode works differently in each.

AreaWPA2WPA3
Personal authenticationPre-shared key with the 4-way handshakeSimultaneous Authentication of Equals (SAE)
Offline password guessingPossible once the handshake is capturedBlocked by SAE, even with a weak passphrase
Forward secrecyNone. A recovered key exposes earlier capturesEvery session derives its own key
Protected management framesOptional (802.11w)Always required
EncryptionAES-CCMP, 128-bitAES-CCMP 128-bit, with an optional 192-bit Enterprise mode
Open and guest networksTraffic sent in the clearEnhanced Open (OWE) encrypts unauthenticated clients
Mixed clientsOne SSID carries one security typeTransition mode lets WPA2 and WPA3 clients share an SSID

This task needs WPA2 Personal with AES. Selecting WPA3 changes the key exchange, so a client that only knows WPA2-PSK will not associate.

Connect a WPA2-PSK client

Create and enable Study-Lab, map it to VLAN 20, select WPA2 Personal with AES, and use the practice key PracticeOnly-20. The client already has that SSID and key configured. Its access point is joined to the controller; you must also make the client VLAN reachable and provide addressing.

Use only the supplied fictitious key. This is an educational GUI model, not a vendor controller or a real wireless connection.

Review WLC questionsReview wireless fundamentals