Security Fundamentals // Lesson 10

WLAN with WPA2-PSK.

Interpret and verify wireless LAN controller GUI settings for a client WLAN protected by WPA2 pre-shared key.

WLAN profileSSIDWPA2PSKClient test
01 // Mental model

Start with the big picture.

The controller uses an internal profile name and advertises a client-visible SSID.

CCNA focus: When association succeeds but traffic fails, move beyond the PSK: check interface/VLAN mapping, switch trunks, DHCP relay, gateway routing, ACLs and DNS.
02 // Building blocks

Know what each part does.

01

Profile and SSID

The controller uses an internal profile name and advertises a client-visible SSID.

02

Interface mapping

The WLAN maps clients to the intended dynamic interface or VLAN.

03

Security

WPA2 with AES and a strong PSK protects association and data without individual user identity.

04

End-to-end verification

A successful test includes association, authentication, DHCP, gateway, DNS and application reachability.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
Layer 2 securityChoose WPA2 policy and AES/CCMP; avoid TKIP where modern security is required.
PSK formatConfigure the same strong passphrase on controller and clients.
QoS profileSelect treatment appropriate to the WLAN's application needs.
Advanced settingsReview client exclusion, session timeout, band and policy features rather than accepting unknown defaults.
04 // GUI workflow

GUI workflow.

1. WLANs -> Create New
2. Set profile name and SSID
3. Map to the intended interface/VLAN
4. Security -> Layer 2 -> WPA2 policy
5. Enable AES and PSK authentication
6. Enter a strong pre-shared key
7. Choose QoS and review advanced settings
8. Enable WLAN and test a client

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • Choose WPA2 policy and AES/CCMP; avoid TKIP where modern security is required.
  • Configure the same strong passphrase on controller and clients.
  • Select treatment appropriate to the WLAN's application needs.
  • Review client exclusion, session timeout, band and policy features rather than accepting unknown defaults.
Exam checkpoint: When association succeeds but traffic fails, move beyond the PSK: check interface/VLAN mapping, switch trunks, DHCP relay, gateway routing, ACLs and DNS.
06 // Check yourself

WLAN with WPA2-PSK quiz.

1. What is the client-visible wireless network name?

2. What must a PSK client and WLAN share?

3. Which cipher should be selected with WPA2 for modern CCNA scenarios?

4. What maps wireless clients onto the wired network?

5. A client authenticates but receives no IP. What should be checked?

Score: 0 / 5