Compare WPA, WPA2 and WPA3, personal and enterprise authentication, and the weaknesses of legacy wireless protection.
WPAWPA2WPA3PSK802.1X
01 // Mental model
Start with the big picture.
A legacy transition from WEP, commonly associated with TKIP; it should not be chosen for new secure deployments.
CCNA focus: The SSID is not a security boundary by itself. Select modern encryption and authentication, protect management access and segment wireless clients according to risk.
02 // Building blocks
Know what each part does.
01
WPA
A legacy transition from WEP, commonly associated with TKIP; it should not be chosen for new secure deployments.
02
WPA2
Uses the IEEE 802.11i security model and commonly AES-CCMP; still widely encountered.
03
WPA3
Modernises personal authentication with SAE and strengthens protections, subject to client and infrastructure support.
04
Personal vs enterprise
Personal uses a shared credential; enterprise uses 802.1X/EAP with per-user or per-device authentication.
03 // Compare and recognise
Read the clues.
Item
What to remember
WEP
Broken legacy protection; do not use.
TKIP
Legacy mechanism associated with WPA; avoid.
AES-CCMP
Common WPA2 data-confidentiality and integrity mechanism.
SAE
WPA3-Personal password-authenticated key exchange resistant to offline guessing in the way PSK handshakes are not.
04 // Protocol choice
Protocol choice.
Home / small office: Prefer WPA3-Personal where every client supports it Otherwise use WPA2-AES with a long unique passphraseEnterprise: Use WPA2-Enterprise or WPA3-Enterprise Authenticate through 802.1X/EAP and RADIUS Validate server certificates on clients
Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.
05 // Exam and troubleshooting
Turn facts into a method.
Broken legacy protection; do not use.
Legacy mechanism associated with WPA; avoid.
Common WPA2 data-confidentiality and integrity mechanism.
WPA3-Personal password-authenticated key exchange resistant to offline guessing in the way PSK handshakes are not.
Exam checkpoint: The SSID is not a security boundary by itself. Select modern encryption and authentication, protect management access and segment wireless clients according to risk.
06 // Check yourself
Wireless Security Protocols quiz.
1. Which protocol is broken and should not be used?
2. Which algorithm is commonly associated with WPA2?
3. What does WPA3-Personal use instead of the classic PSK handshake?
4. What does enterprise wireless commonly use for individual identity?
5. Is hiding the SSID a substitute for encryption?