Wi-Fi Security Modes and Client Capability Interoperability Matrix
1 min
security mode client connect behaviour configuration push to wifi 6e aps configuration push to wifi 7 aps 2 4 ghz / 5 ghz 6 ghz 2 4 ghz / 5 ghz 6 ghz open 802 11be (wi fi 7 client) ✅ yes open authentication no akm 🚫 no ssid on 6ghz open authentication no akm 🚫 no ssid on 6ghz 802 11ax (w fi 6 client) ✅ yes legacy client (wi fi 5 or lower) ✅ yes enhanced open (strict) 802 11be (wi fi 7 client) ✅ yes with mlo (owe) owe (ccmp 128) with pmf enabled akm 00 0f ac 18 note pmf is mandatory for owe owe + (gcmp 256 / ccmp 128) with mlo enabled, pmf enabled akm 00 0f ac 18 note gcmp 256 (required for wi fi 7), ccmp 128 (<=wifi 6e) 802 11ax (w fi 6 client) ✅ yes (owe) legacy client (wi fi 5 or lower) 🚫 no enhanced open (transition) 802 11be (wi fi 7 client) ✅ yes with mlo (owe) dual ssids (1 open, 2 owe) open authentication no akm owe (ccmp 128) with pmf enabled akm 00 0f ac 18 owe (ccmp 128) with pmf enabled akm 00 0f ac 18 dual ssids (1 open, 2 owe) open authentication no akm owe (ccmp 128 / gcmp 256) with mlo enabled, optional pmf akm 00 0f ac 18 note wi fi enhanced open transition mode is disallowed on bsss with eht or mlo enabled if the network includes eht or mlo aps and needs to support legacy stas (that do not support wi fi enhanced open) then the network should be configured with dual ssids owe (ccmp 128 / gcmp 256) with mlo enabled, pmf enabled akm 00 0f ac 18 for mlo every band in mld must use the same akm 802 11ax (w fi 6 client) ✅ yes (owe) legacy client (wi fi 5 or lower) ✅ yes (open) wpa2 personal 802 11be (wi fi 7 client) ✅ yes wpa2 psk akm 00 0f ac 2 (psk), 00 0f ac 4 (psk+ft) 🚫 no ssid on 6ghz wpa2 psk akm 00 0f ac 2 (psk), 00 0f ac 4 (psk+ft) 🚫 no ssid on 6ghz 802 11ax (w fi 6 client) ✅ yes legacy client (wi fi 5 or lower) ✅ yes wpa3 personal (strict) 802 11be (wi fi 7 client) ✅ yes with mlo (wpa3 sae) wpa3 sae with pmf enabled cipher ccmp 128 akm 00 0f ac 8 (sae), 00 0f ac 9 (sae+ft) wpa3 sae with mlo enabled, pmf enabled cipher ccmp 128 / gcmp 256 akm 00 0f ac 8 (sae), 00 0f ac 9 (sae+ft), 00 0f ac 24 (sae h2e), 00 0f ac 25 (ft sae ext key) 802 11ax (w fi 6 client) ✅ yes (wpa3 sae) if os/driver support wpa3 legacy client (wi fi 5 or lower) 🚫 no wpa3 personal (transition) wpa2/wpa3 802 11be (wi fi 7 client) ✅ yes with mlo (wpa3 sae) wpa3 sae and wpa2 psk with optional pmf cipher ccmp 128 akm 00 0f ac 2 (psk), 00 0f ac 4 (psk+ft), 00 0f ac 8 (sae), 00 0f ac 9 (sae+ft) wpa3 sae with pmf enabled cipher ccmp 128 akm 00 0f ac 8 (sae), 00 0f ac 9 (sae+ft) wpa3 sae with mlo enabled and wpa2 psk with optional pmf cipher ccmp 128 / gcmp 256 akm 00 0f ac 2 (psk), 00 0f ac 4 (psk+ft), 00 0f ac 8 (sae), 00 0f ac 9 (sae+ft), 00 0f ac 24 (sae h2e), 00 0f ac 25 (ft sae ext key) for mlo every band in mld must use the same akm wpa3 sae with mlo enabled, pmf enabled cipher ccmp 128 / gcmp 256 akm 00 0f ac 8 (sae), 00 0f ac 9 (sae+ft), 00 0f ac 24 (sae h2e), 00 0f ac 25 (ft sae ext key) for mlo every band in mld must use the same akm 802 11ax (w fi 6 client) ✅ yes (wpa3 sae) if os/driver support wpa3 legacy client (wi fi 5 or lower) ✅ yes (wpa2 psk) wpa2 enterprise 802 11be (wi fi 7 client) ✅ yes wpa2 enterprise akm 00 0f ac 1 (802 1x), 00 0f ac 3 (802 1x+ft), 00 0f ac 5 (802 1x+sha256) 🚫 no ssid on 6ghz wpa2 enterprise akm 00 0f ac 1 (802 1x), 00 0f ac 3 (802 1x+ft), 00 0f ac 5 (802 1x+sha256) 🚫 no ssid on 6ghz 802 11ax (w fi 6 client) ✅ yes legacy client (wi fi 5 or lower) ✅ yes wpa3 enterprise (192 bit) wpa3 only 802 11be (wi fi 7 client) ✅ yes with mlo wpa3 enterprise (192 bit) with pmf enabled cipher gcmp 256 akm 00 0f ac 12 (802 1x sha 384), 00 0f ac 13 (ft+ 802 1x sha 384) wpa3 enterprise (192 bit) with mlo enabled, pmf enabled cipher gcmp 256 akm 00 0f ac 12 (802 1x sha 384), 00 0f ac 13 (ft+ 802 1x sha 384) 802 11ax (w fi 6 client) ✅ yes only if os/driver supports wpa3 legacy client (<=wi fi 5) 🚫 no wpa3 enterprise (128 bit) wpa3 only 802 11be (wi fi 7 client) ✅ yes with mlo wpa3 enterprise (128 bit) with pmf enabled cipher ccmp 128 akm 00 0f ac 5 (802 1x+sha256), 00 0f ac 11 (ft + 802 1x sha256) wpa3 enterprise (128 bit) with mlo enabled, pmf enabled cipher ccmp 128 akm 00 0f ac 5 (802 1x+sha256), 00 0f ac 11 (ft + 802 1x sha256) for mlo every band in mld must use the same akm 802 11ax (w fi 6 client) ✅ yes only if os/driver supports wpa3 legacy client (<=wi fi 5) 🚫 no wpa3 enterprise (transition) wpa2/ wpa3 802 11be (wi fi 7 client) ✅ yes wpa3/wpa2 enterprise (128 bit) with optional pmf cipher ccmp 128 akm 00 0f ac 1 (802 1x), 00 0f ac 3 (802 1x+ft), 00 0f ac 5 (802 1x+sha256), 00 0f ac 11 (ft + 802 1x sha256) wpa3 enterprise (128 bit) with pmf enabled cipher ccmp 128 akm 00 0f ac 5 (802 1x+sha256), 00 0f ac 11 (ft + 802 1x sha256) wpa3/wpa2 enterprise (128 bit) with optional pmf, mlo enabled cipher ccmp 128 akm 00 0f ac 1 (802 1x), 00 0f ac 3 (802 1x+ft), 00 0f ac 5 (802 1x+sha256), 00 0f ac 11 (ft + 802 1x sha256) for mlo every band in mld must use the same akm wpa3 enterprise (128 bit) with mlo enabled, pmf enabled cipher ccmp 128 akm 00 0f ac 5 (802 1x+sha256), 00 0f ac 11 (ft + 802 1x sha256) for mlo every band in mld must use the same akm 802 11ax (w fi 6 client) ✅ yes legacy client (wi fi 5 or lower) 🚫 no

