NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

psghosh's avatar
psghosh
Follower
Nov 28, 2015

EX6200 not enabling AES on WPA2-only option

I have an EX6200 acting as an AP with the most recent firmware( V1.0.3.68_1.1.104), and when I select the WPA2-PSK option for both bands, I noticed on both my laptop and WiFi survey device that TKIP encryption is used (with no AES option), which shouldn't even be a selectable option for WPA2 (only WPA supports the ability to select TKIP or AES, as the WPA2 spec enforced the stronger AES encryption method). TKIP also caps speed on both bands at 54Mbps (so even though it's reporting AC and N capability, TKIP downgrades throughput). If I select the option to support both WPA & WPA2, only then can I see AES-encryption on WPA2 and support for more than 54Mbps. However, I prefer not to leave open WPA as a negotiable option and enforce WPA2. This seems like a rather serious bug! 

 

---Peter Ghosh, CISSP

 

 

5 Replies

  • That sounds pretty strange.  Try setting encryption to None, Apply, then set to WPA2-PSK [AES], and Apply.  I've heard of cases where this would work.

  • I'm having the same issue with my EX6200. All devices indicate that the encryption is WPA2-PSK-TKIP and not WPA2-PSK-AES as selected on the config screen.

     

    This is with the latest firmware:  V1.0.3.68_1.1.104

    • darsovit's avatar
      darsovit
      Aspirant

      Also, there is no option on security to set it to "None".

       

      It's either "WPA2-PSK [AES]" or "WPA-PSK [TKIP] + WPA2-PSK [AES]". I've tried setting it to the latter and a message pops up about only supporting G and not N with those settings. When I've set it to the latter I do see that the mode reported in Wifi Analyzer (on android phone) is WPA-PSK-CCMP and WPA2-PSK-CCMP+TKIP, but when I put it back to WPA2-PSK [AES], it goes back to WPA2-PSK-TKIP (not CCMP).

  • I'm having the exact same issue. It's frustrating because when I select both TKIP and AES on the EX6200, it will work, however, WPA with TKIP is way more vulnerable, security-wise, and I would prefer to have it disabled on the EX6200.  I'm hoping their next firmware addresses this.