Wi‑Fi Security Operating Modes
Transition Mode SSIDs in WPA3-Personal and WPA3-Enterprise Tri‑Band Networks:
Transition mode SSID is designed to support legacy clients by allowing them to connect with lower security settings while still using the same SSID.
WPA3-Personal (Transition mode) SSID: On a tri-band AP, this mode allows 2.4 GHz and 5 GHz clients to connect using either WPA3-SAE or WPA2-PSK, while 6 GHz clients are restricted to WPA3-SAE only.
WPA3-Enterprise (Transition mode) SSID: On a tri-band AP, this mode allows 2.4 GHz and 5 GHz clients to connect using either WPA3-802.1X or WPA2-802.1X authentication. The SSID will not broadcast on the 6 GHz radio when using Transition mode.
WPA3-Enterprise (192-bit Strict mode) SSID: For WPA3-Enterprise deployments, the RADIUS server must present X.509 certificates that comply with contemporary cryptographic best practices and the stricter requirements of WPA3-Enterprise. In practice, this generally means using RSA keys of at least 2048 bits (with 3072 bits or larger recommended for long-lived certificates or 192-bit security profiles), or elliptic-curve (ECDSA) certificates based on strong curves such as P-256 or stronger. Certificates should be signed using SHA-256 or a stronger hash function, and deprecated parameters such as 1024-bit RSA keys or SHA-1 signatures must be avoided.
This table summarizes how different Wi‑Fi security operating modes are applied and broadcast across the 2.4 GHz, 5 GHz, and 6 GHz bands.
Security Mode | Wi‑Fi configuration on 2.4 GHz | Wi‑Fi configuration on 5 GHz | Wi‑Fi configuration on 6 GHz |
|---|---|---|---|
Legacy open | Open | Open | No SSID will be configured on the 6 GHz radio |
OWE (Strict mode) | OWE (Strict) | OWE (Strict) | OWE (Strict) |
OWE (Transition mode) | OWE (Transition) | OWE (Transition) | The SSID will be converted to OWE (Strict) and broadcast |
WPA2‑Personal (UPSK supported) | OWE (Transition) | WPA2‑Personal | No SSID will be configured on the 6 GHz radio |
WPA2‑Enterprise | WPA2‑Enterprise | WPA2‑Enterprise | No SSID will be configured on the 6 GHz radio |
WPA3‑Personal (Strict mode) – UPSK not supported due to standards limitation | WPA3‑Personal (Strict) | WPA3‑Personal (Strict) | WPA3‑Personal (Strict) |
WPA3‑Personal (Transition mode) – UPSK not supported due to standards limitation | WPA3‑Personal (Transition) | WPA3‑Personal (Transition) | The SSID will be converted to WPA3-Personal (Strict) and broadcast |
WPA3‑Enterprise 192‑bit (Strict mode) | WPA3‑Enterprise 192‑bit (Strict) | WPA3‑Enterprise 192‑bit (Strict) | WPA3‑Enterprise 192‑bit (Strict) |
WPA3‑Enterprise (Transition mode) | WPA3‑Enterprise (Transition) – 128‑bit | WPA3‑Enterprise (Transition) – 128‑bit | No SSID will be configured on 6 GHz |
Captive portal with legacy open SSID | Captive portal with legacy open SSID | Captive portal with legacy open SSID | No SSID will be configured on 6 GHz |
Captive portal with OWE transition SSID – Guest SSID defaults to OWE transition, not open | Captive portal with OWE transition SSID | Captive portal with OWE transition SSID | Captive portal with OWE (Strict) SSID will be used |