A visible SSID is only the beginning.
Work through the settings that turn a WLAN into a usable client connection. This free exercise covers configuration choices and troubleshooting dependencies without requiring a controller.
WPA2 and WPA3: what changes
The Security tab below offers both. They protect the same WLAN, but the personal mode works differently in each.
| Area | WPA2 | WPA3 |
|---|---|---|
| Personal authentication | Pre-shared key with the 4-way handshake | Simultaneous Authentication of Equals (SAE) |
| Offline password guessing | Possible once the handshake is captured | Blocked by SAE, even with a weak passphrase |
| Forward secrecy | None. A recovered key exposes earlier captures | Every session derives its own key |
| Protected management frames | Optional (802.11w) | Always required |
| Encryption | AES-CCMP, 128-bit | AES-CCMP 128-bit, with an optional 192-bit Enterprise mode |
| Open and guest networks | Traffic sent in the clear | Enhanced Open (OWE) encrypts unauthenticated clients |
| Mixed clients | One SSID carries one security type | Transition mode lets WPA2 and WPA3 clients share an SSID |
This task needs WPA2 Personal with AES. Selecting WPA3 changes the key exchange, so a client that only knows WPA2-PSK will not associate.
Connect a WPA2-PSK client
Create and enable Study-Lab, map it to VLAN 20, select WPA2 Personal with AES, and use the practice key PracticeOnly-20. The client already has that SSID and key configured. Its access point is joined to the controller; you must also make the client VLAN reachable and provide addressing.
Use only the supplied fictitious key. This is an educational GUI model, not a vendor controller or a real wireless connection.