Community discussions

MikroTik App
 
AllexRo
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 77
Joined: Fri Nov 22, 2019 4:24 pm
Location: Bucharest, RO

Wifi Wave2 - best practice reg. configuration

Sun Mar 27, 2022 2:55 pm

Regarding Wifi Wave2 drivers and setting them up, could someone share must-have/best practice settings, especially for the security module?

My current setup is a pair of Audience, running 7.2rc5 with Wave2 drivers.
I had no issues setting up the Configuration & Channel module, however I'm not sure what is considered an ok config for the security tab.
Currently, my setup is this:
- authentication types: WPA2 PSK , WPA3 PSK
- encryption: CCMP. CCMP 256
- passphrase
- disable PMKID
- WPS: disable
and.. that's all.

Should I have anything else checked? Or changed in my current config?
With the current config, there's only one device that won't connect unless unchecking WPA3, a Oneplus9 (key handshake failure).
Should I add something to the above config? Or just give up on using WPA3?
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11591
Joined: Thu Mar 03, 2016 10:23 pm

Re: Wifi Wave2 - best practice reg. configuration

Sun Mar 27, 2022 3:24 pm

Try to add gcmp and gcmp-256 to the encryption list. They come with wpa3 and some implementers might think it's required to use some gcmp cipher with wpa3.
 
AllexRo
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 77
Joined: Fri Nov 22, 2019 4:24 pm
Location: Bucharest, RO

Re: Wifi Wave2 - best practice reg. configuration

Sun Mar 27, 2022 10:46 pm

Thanks, mkx.
I've added both gcmps and now Oneplus randomly connects - which is an improvement from not connecting at all.
Probably something in Oxygen OS doesn't like Mikrotik's approach to WPA3.
 
User avatar
Hominidae
Member
Member
Posts: 309
Joined: Thu Oct 19, 2017 12:50 am

Re: Wifi Wave2 - best practice reg. configuration

Mon Mar 28, 2022 6:00 pm

Try to add gcmp and gcmp-256 to the encryption list.
I've added both gcmps [...]
...ehhrmm...how did you actually do that? I can only select one item out of the possible list in the group encryption entry under the security tab.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11591
Joined: Thu Mar 03, 2016 10:23 pm

Re: Wifi Wave2 - best practice reg. configuration

Mon Mar 28, 2022 8:10 pm

Try to add gcmp and gcmp-256 to the encryption list.
I've added both gcmps [...]
...ehhrmm...how did you actually do that? I can only select one item out of the possible list in the group encryption entry under the security tab.

Can't say about winbox, in webfig all the options have check boxes and it's possible to enable multiple choices. In CLI, you set it like this: set 0 security.encryption=ccmp,gcmp,ccmp-256,gcmp-256 ...
 
User avatar
Hominidae
Member
Member
Posts: 309
Joined: Thu Oct 19, 2017 12:50 am

Re: Wifi Wave2 - best practice reg. configuration

Tue Mar 29, 2022 4:38 pm

meeeh..yes, the encryption segment is per default hidden in webfig and winbox...no wonder, I didn't see it with my old eyes...I am balding fast
 
AllexRo
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 77
Joined: Fri Nov 22, 2019 4:24 pm
Location: Bucharest, RO

Re: Wifi Wave2 - best practice reg. configuration

Sun Apr 03, 2022 4:46 pm

How should interpret the fact that, if I make no settings under the encryption area of the Security settings tab of Wireless, 2 devices that previously had problems now connect without any issues?
Basically CCMP/CCMP256/GCMP/GCMP256 are no longer checked, while WPA2PSK/WPA3PSK are still checked.. and this solved the issue.

Is this safe to keep like this?
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11591
Joined: Thu Mar 03, 2016 10:23 pm

Re: Wifi Wave2 - best practice reg. configuration

Sun Apr 03, 2022 5:05 pm

Official wifiwave2 documentation mentions default settings. For encryption in particular it says that it defaults to "ccmp" only. Which incidentally is the only real WPA2 key exchange algorithm (tied with aes encryption algorithm), TKIP is a WPA (first gen).

Personally I don't like empty settings, because hard-coded defaults can change out-of-sync with documentation. I'd rather see property which has default value set in initialisation script while empty value would trigger error message and non-operational interface.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19323
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Wifi Wave2 - best practice reg. configuration

Sun Apr 03, 2022 5:14 pm

Best practice............. put it on a shelf, and wait for maturity of software.
 
User avatar
Hominidae
Member
Member
Posts: 309
Joined: Thu Oct 19, 2017 12:50 am

Re: Wifi Wave2 - best practice reg. configuration

Sun Apr 03, 2022 11:59 pm

...better practice....try it out, go through the dungeons of configurations without the ability to use capsman....once you are there, keep it and never look back...maybe software will evolve over time.

I would not trade my hap-ac3 units anymore...definitely, they are not on a shelve...my cap-ac and wap-ac are.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19323
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Wifi Wave2 - best practice reg. configuration

Mon Apr 04, 2022 2:30 am

...better practice....try it out, go through the dungeons of configurations without the ability to use capsman....once you are there, keep it and never look back...maybe software will evolve over time.

I would not trade my hap-ac3 units anymore...definitely, they are not on a shelve...my cap-ac and wap-ac are.
I will wait for next Gen WIFI, I much prefer the performance as per my other business access points, but prefer having that tech with RoS flexibility.
 
User avatar
Hominidae
Member
Member
Posts: 309
Joined: Thu Oct 19, 2017 12:50 am

Re: Wifi Wave2 - best practice reg. configuration

Mon Apr 04, 2022 11:40 am

...the point is, hence the reference to putting in on a shelve: if you already own one, then do use it. ...if you are looking for better performance but start with new hardware....go elsewhere or wait.
 
AllexRo
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 77
Joined: Fri Nov 22, 2019 4:24 pm
Location: Bucharest, RO

Re: Wifi Wave2 - best practice reg. configuration

Mon Apr 04, 2022 12:17 pm

As a home user with a relatively simple network, I'm quite ok with Audience running 7.x. To be honest, even with Mikrotik proprietary drivers, wireless performance feels significantly better than it was before. So I'm not considering shelfing them.. yet :D
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19323
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Wifi Wave2 - best practice reg. configuration

Mon Apr 04, 2022 4:57 pm

Got it, and yes I still use one capac, didnt replace them all with other products. The others are gathering dust.

Who is online

Users browsing this forum: Ahrefs [Bot], dewitpj, rkau045 and 27 guests