TechKnowSurge
Cisco CCNA 5.10 Cisco CCNA 2.9 Cisco CCNA 5.9 Cisco CCNA 2.6
VideoNetworkFree

DEMO: Configure WPA2 PSK

Covers wireless LAN configuration on a Cisco Wireless LAN Controller, including WPA2 security settings and PSK authentication to enable client connectivity on a VLAN-segmented network.

Complete this video to capture a CTF flag worth 1 point.

About this video

Configuring a wireless LAN on a Cisco Wireless LAN Controller requires navigating the web-based management interface to access and modify an existing WLAN profile. This content focuses on a WLAN associated with VLAN 10, walking through the security tab to select appropriate layer 2 security settings. WPA combined with WPA2 is chosen as the encryption standard, with the configuration scoped specifically to WPA2 policy for stronger protection. For authentication, 802.1X is set aside in favor of a pre-shared key, which offers a straightforward setup path while still maintaining meaningful security. The PSK is configured in ASCII format, with emphasis on selecting a passphrase that is both complex enough to resist guessing and practical enough to distribute within an organization. Once applied, the controller briefly disables the WLAN to process the change before restoring it with the new settings. A successful client connection to the secured SSID confirms the configuration is functioning as expected, establishing a foundation before more advanced authentication methods such as 802.1X and certificate-based access are introduced.

What you'll learn

What's covered

Configuring Wireless LANs

Aligned to

Cisco CCNA
5.10 Configure and verify WLAN within the GUI using WPA2 PSK
2.9 Interpret the wireless LAN GUI configuration for client connectivity
5.9 Describe wireless security protocols
2.6 Describe Cisco Wireless Architectures and AP modes

Key terms

Wireless LAN Controller
WLC
A network device that provides centralized management of multiple lightweight wireless access points, handling functions such as client authentication, roaming, radio frequency management, and security policy enforcement. WLCs communicate with APs using CAPWAP and allow network-wide wireless configuration from a single management point.
Service Set Identifier
SSID
The network name broadcast by a wireless access point that clients use to identify and connect to a specific Wi-Fi network. SSIDs can be up to 32 characters long and are transmitted in beacon frames; networks may be configured to suppress SSID broadcasting for limited obscurity.
Wi-Fi Protected Access 2
WPA2
An IEEE 802.11i-compliant wireless security certification that mandates AES-based CCMP encryption, providing substantially stronger data protection than WPA's TKIP. WPA2 supports both Personal mode (pre-shared key) and Enterprise mode (802.1X/RADIUS authentication).
Pre-Shared Key
PSK
A shared secret passphrase used for authentication in wireless networks and VPNs without requiring a dedicated authentication server. In WPA-Personal mode, the PSK is used to derive the Pairwise Master Key (PMK) for encrypting the wireless session.
Virtual LAN
VLAN
A logical grouping of network devices that behave as if they are on the same network regardless of physical location.
Advanced Encryption Standard
AES
A symmetric encryption algorithm widely used to secure data, supporting key sizes of 128, 192, and 256 bits.

Topics

Wireless Networking Wpa2 Psk Authentication Cisco Wlc Wireless Lan Vlan

Transcript

Now that we have our wireless access points set up, we need to start configuring our wireless LANs on the network. When we went through the initial setup of our wireless LAN controller, one of the things we set up is a wireless LAN for our VLAN 10.

Opening the wireless LAN

Through the web interface of this wireless LAN controller, we're going to actually do the configuration of our wireless LAN. I'm going to select wireless LAN from the top menu here, and we can see the wireless LAN that was set up during the initial configuration of this wireless LAN controller. I'm going to get into it by selecting the first wireless LAN ID. I'll select into it, and then I get some configurations of this wireless LAN.

I can change the profile name, I can change the SSID, neither of which I want to do. What I want to configure on here is the security. I need to set up the security so I can actually connect to it. So we can see the tab here, security; there's also QoS, policy mapping, advanced. For now we're just going to take a look at the security tab.

Layer 2 security

When I look at this I can say, okay, layer 2 security, what do I want to use? I can use WEP or I can use WPA plus WPA2. There's different items that I can select in here. I'm just going to keep it as WPA and WPA2; that's pretty standard.

Then next what I'll do is I'll see that in the WPA/WPA2 parameters I have just the WPA2 policy selected, so this will be connecting with WPA2.

Then down here, what's the authentication method? This WPA/WPA2 is going to be the encryption, and how it's going to be encrypted and send this information back and forth. But how are we going to authenticate? The 802.1X is a way that we can use certificates or usernames and passwords, and we will be covering that a little bit later, but for now I just want to set up a passkey. A passkey is one of the simplest ways we can set up WPA. So I'm going to uncheck 802.1X and I'm going to select PSK, or the passkey.

Setting the passkey

When I select that, you'll see that there's a couple of fields down here that appear. I can select the passkey format, so it's selected as ASCII, but I can also do a hex number. And then I give it a passkey format. So this is where I would come up with some sort of passkey that's going to be hard to hack and not easily guessable, but something that I can convey to the people at my company. Since this is the management network, I want it more secure; I don't want anyone to be able to guess it.

So what I'm going to do is create a key for this. I'll call it, how about TKS, or what is the name of this? So I'm going to call it tks10. It does not need a username, but it does need a password, so I'm going to take this password right here, I'll copy it, and I'm going to paste it into here. I'll click OK. I always would like to save this.

All right, so that's my passkey in there, and then I do have to hit apply. So it's going to let me know that changing this parameter is going to cause the wireless LAN to momentarily be disabled and thus may result in loss of connectivity. Well, I don't have anything connected to it yet, so that's fine. I'm going to click OK, and now it's going through the process of applying. Once I've confirmed this, I'm going to want to make sure that this configuration is saved as well.

Connecting to the network

So let's see if we can connect. What I'm going to do is open up my tray down here, and actually it's this network connection right here, and I can see TKS-10 is selected right here. So I'm going to select that, I'll click connect to this, I'll paste in the password into here, hit next. And do we want this computer to be recognizable on the network? I'm going to click no on that one.

Now it's going to go through the process of connecting to this network right here. At this point in time we see that it says secured, although there is no internet. So what that is doing is it's secured, so we're connected, we made a connection, everything is connected fine, except that it tried to reach out through this connection and see if it can reach the outside world and determined it can't. So that's fine, I don't have this network set up where it can reach the outside world at this point. So we are good to go, this can connect, and we've set up WPA2.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →