12.4 PMF, Fast Roaming, WIPS and Secure Management

Key Takeaways

  • Choose access control to match identity: captive portal for guest AUP, PSK/SAE for scoped devices, 802.1X for employees.
  • Protected Management Frames (802.11w) integrity-protect deauthentication, disassociation, and other robust management frames; WPA3 requires PMF.
  • OKC and 802.11r FT shorten 802.1X roams by reusing key context so voice and real-time sessions survive BSS transitions.
  • A rogue AP is an unauthorized AP on your wired network; an interfering or neighbor AP contends in RF without that wired attachment.
  • Manage infrastructure with SSH and HTTPS, not Telnet or HTTP, and with SNMPv3 rather than community-string SNMPv1/v2c.
Last updated: September 2026

Objective 5.4 asks you to describe common security options and tools used on wireless networks: access control solutions, Protected Management Frames, fast secure roaming, WIPS and rogue detection, protocol and spectrum analyzers, and secure management protocols. Domain 5 is still 10 percent of CWNA-109, but this objective is where architecture, voice design, and day-two operations meet. You are selecting who is allowed on which SSID, keeping management frames from being spoofed, keeping 802.1X users in a call while they roam, noticing an AP that should not be on your switch, and not administering the controller over Telnet.

Access control solutions: captive portal, 802.1X, and PSK

Pick the control that matches the identity you actually need.

802.1X / WPA2- or WPA3-Enterprise is the employee and managed-device path. The authenticator holds the virtual port closed until RADIUS returns Access-Accept. You get a user or certificate identity, dynamic keys, VLAN/ACL attributes, and revocation. Pair it with NAC or MDM when you must check posture (disk encryption, OS version) or auto-enroll EAP-TLS certificates for BYOD. That is access control in the strong sense.

PSK or SAE is a shared (or per-device vendor) secret. Use it for IoT, printers, and small offices that cannot run a supplicant against AAA. WPA3-SAE is the better password mode when clients support it. Do not put staff laptops on the same PSK SSID as a lobby TV.

Captive portal (web authentication) is a layer-7 click-through after the station already has some 802.11 connectivity—often on open, OWE, or a guest PSK. The portal enforces an acceptable-use page, sponsors guest accounts, or bills a hotel stay. It is not 802.1X. After login, many systems authorize by MAC address, which is spoofable; mitigate with short session timeouts, client isolation, a guest VLAN with no path to internal prefixes, and rate limits. Never place a captive-portal guest SSID on the employee VLAN. BYOD onboarding portals that install a certificate and then move the device to 802.1X are a different, better pattern than leaving guests on MAC-auth forever.

MethodProves at 802.11/AAATypical SSIDFailure if misused
802.1X + EAPUser or device identity, per-session keysStaff, managed endpointsSlow roams without FT/OKC; PEAP without cert validation
PSK / SAEKnowledge of a passwordIoT, tiny officeShared PSK: no per-user revoke; WPA2-PSK offline grind
Captive portalWeb login / AUP after joinGuest, venue Wi-FiMAC-based session; open sniffing unless OWE; easy to skip isolation

Protected Management Frames (IEEE 802.11w)

Protected Management Frames (PMF) integrity-protect robust management frames. The important pair on every practice item is deauthentication and disassociation. Without PMF, those frames are unauthenticated. A transmitter that spoofs the AP’s address can tell a STA to leave, which is a cheap denial of service and a way to force reconnects. PMF does not encrypt Beacons and does not hide the SSID. It binds deauth/disassoc (and many Action frames) to keys so a stranger cannot forge them.

Unicast robust management frames use the pairwise key. Broadcast robust management frames use BIP (Broadcast Integrity Protocol) with an integrity GTK (IGTK). The RSN information element advertises MFPC (capable) and MFPR (required):

  • Both zero: PMF off (WPA2 legacy).
  • Capable, not required: mixed BSS; old clients join without PMF; PMF clients should still use it when the AP offers it.
  • Capable and required: only PMF clients join. WPA3-only modes set this.

Enable PMF required on employee SSIDs as soon as the client mix allows. WPA3 already requires it. Expect breakage on antique barcode scanners; give them a dedicated SSID rather than disabling PMF globally. PMF is complementary to AES-CCMP: data confidentiality without management integrity still leaves a kick-off path.

Fast secure roaming: OKC and 802.11r FT

A full 802.1X exchange plus 4-way handshake on every roam can cost hundreds of milliseconds to seconds. Voice, video, and some warehouse scanners drop. Fast secure roaming reuses key context so the STA can install keys with the target AP without repeating EAP to RADIUS.

Opportunistic Key Caching (OKC) is a widely deployed non-IEEE method. After the first 802.1X success, APs in a mobility domain can derive a PMK identifier so a roam completes with a 4-way handshake only. It is simple and usually “on” in controller families, but it is not the IEEE FT protocol.

IEEE 802.11r Fast BSS Transition (FT) is the standard. After an initial mobility-domain association, the STA performs an FT reassociation either over-the-air with the target AP or over-the-DS through the current AP. A shortened handshake installs keys. CWNA wants awareness that 802.11r exists and that it is the standards-based fast-roaming AKM, not a lab in R0KH/R1KH key naming (that depth is CWSP).

Related but distinct: PMK caching and 802.11i preauthentication (EAP to the target through the current AP) are older 802.11i tools. 802.11k neighbor reports and 802.11v BSS transition management help the client choose a roam target; they do not by themselves install keys faster. Voice designs combine coverage overlap, FT or OKC, and often k/v. Fast roaming is not a reason to use PSK “because 802.1X is slow”—it is a reason to turn on FT/OKC on the Enterprise SSID.

WIPS and rogue versus interfering APs

A Wireless Intrusion Prevention System (WIPS) (or WIDS if it only alerts) watches the air and, in integrated architectures, correlates with the wired edge. Classification language matters on the exam:

  • Valid / friendly AP — your infrastructure BSSID, known to the controller or WIPS inventory.
  • Neighbor / interfering AP — an 802.11 device you can hear that is not attached to your wired network. It contends for airtime (co-channel or adjacent) and may be a café next door. It is an RF problem first, a policy problem second. Containing it can disrupt someone else’s legal BSS.
  • Rogue AP — an AP that is unauthorized and connected to your wired LAN (a desk AP on an access port, a misconfigured printer with a soft AP bridged to Ethernet, an attacker who found an open jack). That is a network-security incident: it can bridge your VLAN to an SSID you do not control. WIPS wired correlation (seeing the AP’s MAC on a switch port and in the air) is how products promote a device from “interfering” to “rogue.”

Evil twin is a different story: an AP that imitates your SSID to collect credentials. It may or may not touch your wire. WIPS looks for SSID/BSSID impersonation, unexpected security IEs (your SSID advertised as open), and often location. Response is alert, locate, and wired port disable for true rogues; RF containment is a policy decision with legal and safety implications—know that the button exists, and that blindly containing every heard BSSID is how you attack the clinic next door.

Sensors may be dedicated overlay radios or APs that off-channel scan. Off-channel scanning is cheaper and misses some time on the serving channel; overlay is more complete. For CWNA, know both exist and that WIPS is how you detect, classify, and optionally prevent—not a substitute for 802.1X on the real SSID.

Protocol analyzers and spectrum analyzers as security visibility

A protocol analyzer (with a NIC in monitor mode) decodes 802.11 MPDUs. For security work you read the RSN information element (AKM, pairwise/group ciphers, MFPC/MFPR), watch EAPOL 4-way and 802.1X exchanges, and match association status codes to mismatches (PMF required vs client incapable, wrong AKM, TKIP where you expected CCMP). You confirm whether a “hidden” SSID is in a probe, whether a guest BSS is truly OWE, and whether deauths are appearing without PMF. It sees frames, not non-Wi-Fi energy.

A spectrum analyzer shows RF energy versus frequency and time: duty cycle, center frequency, pulse patterns. It identifies non-802.11 interferers (microwaves, analog video, some RADAR, poorly shielded cameras) and jamming-like energy that never appears as a valid MPDU. It cannot tell you the EAP method. Security and troubleshooting both need the pair: protocol for policy and handshake truth, spectrum for energy that is not a BSS.

WLAN scanners (client utilities, Ekahau-class tools, controller maps) sit in between: they list BSSIDs, RSSI, and security type without a full frame decode. Use them for inventory and rogue hunting at walking speed, then drop to a protocol capture when the RSN IE must be authoritative.

Secure management protocols

The WLAN can be WPA3-Enterprise and still be owned if the controller GUI is HTTP or the AP Telnet login uses admin/admin. Best practices at CWNA depth:

  • SSH (version 2) for CLI; disable Telnet.
  • HTTPS for GUI and APIs; disable HTTP or redirect it.
  • SNMPv3 with authentication and privacy (authPriv); do not use SNMPv1/v2c community strings on production. If a monitoring tool still needs v2c, isolate it and treat it as technical debt.
  • AAA for administrators (RADIUS or TACACS-style) rather than a shared local password; unique accounts; rotate secrets.
  • Management VLAN or OOB network; do not manage APs from the client SSID.
  • VPN for staff who must reach the WLC from the Internet.
  • NTP so logs and certificates have trustworthy time; central logging.
  • Signed firmware, disable unused services (FTP, HTTP, old SSL), and no default certificates left trusted for admin if the vendor lets you replace them.
Insecure defaultReplace withWhy
TelnetSSHv2Telnet carries credentials and session text in the clear
HTTP GUIHTTPSSame exposure for cookies and admin passwords
SNMPv2c public/privateSNMPv3 authPrivCommunity strings are reusable cleartext secrets
Shared local adminPer-user AAANo attribution and painful rotation

Domain 5 as a whole is a sequence you can recite: refuse WEP, Shared Key, cloaking-as-security, MAC-as-auth, and TKIP; use AES-CCMP/GCMP; prefer 802.1X for people and SAE for password SSIDs; require PMF; encrypt guest with OWE; roam with FT or OKC; classify rogues with WIPS; manage with SSH, HTTPS, and SNMPv3. That is the entire 10 percent, taught as production practice rather than a toolkit of attacks.

Test Your Knowledge

How should a WIPS classify an unknown AP that is heard on channel 36 but has no correlation to any switch port or wired MAC on the corporate LAN?

A
B
C
D
Test Your Knowledge

What problem does Protected Management Frames (IEEE 802.11w) primarily close on a WPA2/WPA3 BSS?

A
B
C
D
Test Your Knowledge

Which set of management-plane practices matches CWNA secure-management guidance for controllers and access points?

A
B
C
D