Creating a Network That Uses a Passphrase (PSK/SAE)
You can create a network that requires users to enter a passphrase (PSK/SAE).
-
On the navigation bar, click
Wi-Fi > Wi-Fi
Networks > Wi-Fi Networks
List.
The Networks page is displayed.
-
Click Add Wi-Fi
Network. Alternatively, select a Passphrase (PSK/SAE) network
setting that you want to copy and click Clone at the top
of the table.
The Create New Network page is displayed.
-
Complete the following settings
on the Network Details page.
- Network Name: Enter a name (2–32 characters) for the network. By default, this name is also used as the SSID.
- (Optional) Set different
SSID: Click Set different
SSID to configure an SSID different from the network
name. The SSID field is displayed.
- SSID: Enter an SSID name (2–32 characters; up to 32 bytes for UTF‑8 non‑Latin characters).
- (Optional) Description: Enter a description to help you identify the network.
- Network Type: Select Passphrase (PSK/SAE).
The structure diagram of a Passphrase (PSK/SAE) network is displayed. -
Click Next.
The Settings page is displayed.
Settings Page
- Passphrase: Enter a passphrase of at least eight characters that users must provide to access the network.
-
(Optional) Security
Protocol: Select the Security Protocol
method. The options include the following:
- WPA2
(Recommended) (default): Select WPA2
(Recommended) and enter a passphrase of at least eight
characters in the Passphrase field.
WPA2 provides strong Wi‑Fi security and is widely supported on devices manufactured after 2006. Select WPA2 unless your deployment requires WPA3. 6 GHz radios are supported only with WPA3.
- WPA3:
Select WPA3 and enter a passphrase of at least eight
characters in the SAE
Passphrase field.
WPA3 provides the highest Wi‑Fi security and is supported on most devices manufactured after 2019.
Note: The IEEE 802.11ax (Wi-Fi 6E) and IEEE 802.11be (Wi-Fi 7) APs support only WPA3. The 6 GHz radios support WPA3 only. - WPA2/WPA3 mixed
mode: Select WPA2/WPA3 mixed
mode and enter a passphrase of at least eight characters
in the WPA2
Passphrase and WPA3 SAE
Passphrase fields.
WPA2/WPA3 mixed mode lets devices connect using either WPA3, the most secure Wi-Fi standard, or WPA2, which is still widely supported. Most devices made after 2006 support WPA2, and those from 2019 onward typically support WPA3.
Note: Select WPA3 or WPA2/WPA3 mixed mode if you broadcast on 6 GHz. - WPA: Select WPA and
enter a passphrase of at least eight characters in the
Passphrase field.
WPA supports legacy devices that do not support WPA2 and were manufactured before 2006. RUCKUS recommends upgrading or replacing these devices because WPA provides weaker security than newer standards. The platform supports 6 GHz radios only when WPA3 is used.
- WEP:
Select WEP and enter a passphrase of at least
eight characters in the Passphrase field.
WEP supports legacy devices that cannot be replaced. WEP is insecure and easily exploitable, and RUCKUS does not recommend its use for protecting wireless networks. Do not transmit sensitive information across networks that use WEP. Because of security concerns, WEP is not supported for new users; existing networks that already use WEP remain unaffected. The system supports 6 GHz radios only with WPA3.
- WPA2
(Recommended) (default): Select WPA2
(Recommended) and enter a passphrase of at least eight
characters in the Passphrase field.
- Management Frame Protection (802.11w): Configure Management Frame Protection (802.11w) when WPA2 (Recommended) is selected. Choose Disabled (default), Optional, or Required depending on the level of protection required for management frames.
-
MAC
Authentication: Toggle the MAC
Authentication switch on to add an additional security layer to
the network. When enabled, the system displays the MAC Registration
List and External MAC Auth
options. The MAC Registration List does not support MAC address format
selection. MAC Authentication is disabled by default.
Note:
-
MAC Authentication enhances security for corporate networks by sending client MAC addresses to the configured RADIUS servers for authentication and accounting. Changing the MAC Authentication setting requires creating new MAC authentication settings; the system does not support editing existing settings.
-
When MAC Authentication is enabled by using either a MAC Registration List or External MAC Auth, the system enables Dynamic VLAN automatically. Access the Dynamic VLAN option by clicking Show more settings and selecting the VLAN sub‑tab.
-
When you configure a MAC Registration List, also create a new Identity profile and associate it with a client device. Refer to Adding an Identity and Adding a Device to an Identity for more information.
-
-
MAC Registration
List: Select MAC Registration
List by clicking the corresponding radio button.
The Select MAC Registration List drop‑down list is displayed. Select an existing MAC registration list or click Add to create a new one. When you click Add, the Add MAC Registration List dialog box is displayed.Note: If MAC registration is enabled, RUCKUS One processes the initial authentication request using the MAC registration list. However, if the MAC registration list is not selected, the request is forwarded to the AAA server.Complete the following to add a new MAC Registration List:
- Name: Enter a name for the MAC Registration List.
- List Expiration: Select an expiration option for the list. Options include Never Expires, By Date (provide an expiration date for the list), or After (provide a duration in hours, days, weeks, months, or years).
- Automatically clean expired entries: Toggle the Automatically clean expired entries switch on to clean expired entries in the list.
- Identity Group: Select an identity group from the drop-down list or click Add to add one. You can also enable Use single identity association to all onboarded devices to assign the same identity to all devices.
- Adaptive Policy Set: Select a policy set from the drop-down list or click Add to add one.
Note: You can associate only one MAC Registration List with each SSID. Adaptive policy sets configured with the MAC Registration List do not apply because external AAA authentication occurs after the policy evaluation stage. -
External MAC
Auth: Select External MAC Auth
by clicking the corresponding radio button.
The MAC Address Format drop-down field is displayed.
- MAC Address
Format: Select the MAC Address
Format from the drop-down list to enable external MAC
authentication. Supported MAC address formats include the following:
- Upper case MAC address separated by colons: 70:EA:5A:78:A1:A0
- Upper case MAC address separated by hyphens: 70-EA-5A-78-A1-A0
- Upper case MAC in a continuous string: 70EA5A78A1A0
- Lower case MAC address separated by colons: 70:ea:5a:78:a1:a0
- Lower case MAC address separated by hyphens: 70-ea-5a-78-a1-a0
- Lower case MAC in a continuous string: 70ea5a78a1a0
- MAC Address
Format: Select the MAC Address
Format from the drop-down list to enable external MAC
authentication. Supported MAC address formats include the following:
-
Accounting
Service: Toggle the switch on to enable this option and select
the existing RADIUS Server from the Accounting Server
drop-down list.
If the server is not available, you can create a new one; click Add Server, complete the fields in the Add AAA server sidebar, and click Add. Then select the newly created RADIUS from the drop‑down list. Refer to Adding and Managing a RADIUS Server.
- Proxy
Service: Toggle the switch on to enable the proxy
service.Note: Use the controller as a proxy in 802.1X networks. When access points send authentication and accounting messages to the controller, the controller forwards these messages to an external AAA server.
- Proxy
Service: Toggle the switch on to enable the proxy
service.
-
Authentication
Service: Toggle the switch on to enable this option and select
the existing RADIUS Server from the Authentication Server
drop-down list.
If the server is not available, you can create a new one; click Add Server, complete the fields in the Add AAA server sidebar, and click Add. Then select the newly created RADIUS from the drop‑down list. Refer to Adding and Managing a RADIUS Server.Note: This field appears only when External MAC Auth is selected.
- Proxy
Service: Toggle the switch on to enable the proxy
service.Note: Use the controller as a proxy in 802.1X networks. When access points send authentication and accounting messages to the controller, the controller forwards these messages to an external AAA server.
- Proxy
Service: Toggle the switch on to enable the proxy
service.
-
Identity Group:
Select an identity group from the drop‑down list.
If the identity group is not yet defined, you can create a new one; click Add, complete the fields in the Create Identity Group sidebar, and click Apply. You can then select the newly created identity group from the Identity Group drop-down list. Refer to Adding an Identity Group for information on how to create a new identity group.
You can click View Details to view the identity group details in the Identity Group sidebar.
Note:- When you select an identity group, all devices that join the network automatically become identities within that group, as shown on the Identity Group page. Users can select an existing identity group or create a new one.
- During network editing, you cannot remove the originally selected identity group; however, you can change it to a different identity group. The identity configuration section does not apply to the MAC Registration List when MAC Authentication is enabled.
- This field appears only when External MAC Auth is selected.
-
(Optional) Use single identity
association to all onboarded devices: Toggle the Use single identity
association to all onboarded devices switch on to enable this
feature.
The Identity field is displayed. When this option is enabled, all devices that connect to this network associate with the selected identity. When this option is disabled, the system creates a separate identity for each connected device within the identity group.
- Click Associate Identity to open the Associate Identity sidebar, select an identity to associate with the identity group, and then click Add.
-
(Optional) Click
Add Identity to open the Create
Identity sidebar and add an identity. Refer to Adding an Identity for
instructions on how to add an identity.
Note: This field appears only when External MAC Auth is selected.
-
Click Show more
settings.
By default, the VLAN sub-tab is displayed. Each sub-tab includes additional Wi-Fi configuration options to configure your preferred settings. Refer to Configuring Additional Settings for a Wi-Fi Network to configure each of the available settings.
Note:Demonstration of Advanced Settings for a Wi-Fi Network. This video explains advanced settings for a Wi-Fi network and walks you through the process of configuring them.
-
Click Next.
The Venues page is displayed.
-
Select one or more venues where you want
to activate this network by clicking the checkbox next to the Venue column, and then toggle
the switch on in the Activated column.
The details in the APs, Radios, and Scheduling columns are displayed for all the activated venues. By default, this network configuration is applicable for All APs and their applicable radio bands, and is scheduled to be available 24/7.
-
Click the All APs hyperlink in the
APs column or the list of
radios in the Radios column of
the Venues section on the Create New Network
page to configure APs and radio-frequency bands for the selected venue.
The Select APs dialog box is displayed. Select one of the following options:
- All APs: Select
All APs to
activate this network on all current and future APs in this venue. Choose a radio
band from the drop-down list. You can choose one or more of the supported radio
bands.
Select APs
- Select specific AP
groups: Select Select specific AP
groups to activate this network on specific AP groups including any
AP that is added to the selected AP groups in the future. The APs not assigned to any
group option is displayed with a checkbox and a reminder to select
an AP Group.
Click the APs not assigned to any group checkbox; the VLAN and Radio Band options are displayed:
Select Specific AP Groups
- In the VLAN option,
VLAN-1 is selected by default. Click the
icon
and select VLAN or pool from the drop-down list. Depending on the selection, enter the
VLAN ID or select the pool from the drop-down list. - In the Radio Band option, select one or more of the supported radio bands from the drop-down list for the selected AP group.
- Click Apply.
- All APs: Select
All APs to
activate this network on all current and future APs in this venue. Choose a radio
band from the drop-down list. You can choose one or more of the supported radio
bands.
-
Click the 24/7 hyperlink in the
Scheduling
column of the Venues section on the Create New
Network page to customize the schedule.
The Schedule for Network <network-name> in Venue <venue-name> dialog box is displayed.
Schedule for Network Dialog Box
- Click Custom Schedule.
- Customize the network schedule as
required. You can configure Monday through Sunday and times from 00:00 to 23:59.
Click the See tips hyperlink for guidance. The
Network Scheduler Tips dialog box is displayed.
Network Scheduler Tips
- Review the tips and click OK to close the Network Scheduler Tips dialog box.
- Click Apply. The hyperlink updates to ON now. When hovered over, it displays the time until which the scheduler will remain active (<Day> <Time>).
-
Toggle the Network Tunneling switch on to
define how network traffic is tunneled at the venue. When toggled on, a Tunnel: <venue-name>
sidebar is displayed.
Note: The Network Tunneling switch is displayed only when the venue is Activated.
- Select a Tunneling Method from the drop-down.
- If you choose SoftGRE, select a
SoftGRE
profile and optionally enable and configure IPsec. (Refer to
Creating a SoftGRE Profile and Adding an SD-LAN Service).
The SD-LAN option is available only when RUCKUS Edge devices are present.
- Click Add to save and apply.
-
Click the All APs hyperlink in the
APs column or the list of
radios in the Radios column of
the Venues section on the Create New Network
page to configure APs and radio-frequency bands for the selected venue.
-
Click Next.
The Summary page is displayed.
- Click Finish.