How to configure PMF on Omada Controller

Omada Software Controller , Omada Cloud-Based Controller
Recent updates may have expanded access to feature(s) discussed in this FAQ. Visit your product's support page, select the correct hardware version for your device, and check either the Datasheet or the firmware section for the latest improvements added to your product. Please note that product availability varies by region, and certain models may not be available in your region.
This article applies to Omada EAPs except EAP110-OutdoorV3/V4,EAP115-Bridge V1,EAP110V4,EAP115V5, EAP690E HD V1, EAP225-Wall V2.
PMF (Protected Management Frames), a standard in the IEEE 802.11w protocol developed by the Wi-Fi Alliance, aims to enhance the security of Wi-Fi connections. It provides unicast and multicast management, and improves security through protecting wireless network management frames, thus solving the problem of malicious attacks caused by disassociation and deauthentication frames.
Follow the steps below to configure PMF on Omada Controller. (PMF configuration is supported only on the Omada Controller, not currently supported in Standalone mode or on the App.)
1. Create a new SSID on the Wireless Networks > WLAN page, as shown in the figure below. The default encryption method is WPA2, and the status of PMF is Disable, indicating that PMF is disabled.
2. To enable the PMF function, choose Mandatory or Capable according to the network security needs. Mandatory requires PMF encryption on the clients; otherwise, the device will not be associated. Capable supports associations with clients that do not support PMF.
Please note that when Mandatory is selected, non-PMF-capable clients may fail to connect to the network.
3. When you select 6GHz or select WPA3 encryption, Disable for PMF status is not selectable. The default status will be Capable to be compatible with clients that do not support PMF.
Notes:
1. Management frames for configuring PMF encryption includes disassociation frames, deauthentication frames and Robust Action frames (Spectrum Management, QoS, DLS, Block Ack, Radio Measurement, Fast BSS Transition, SA Query, Protected Dual of Public Action, Vender-specific Protected). You can check the effect by capturing packets. The above management frames will be in an encrypted state, and MFPR (Management Frame Protection Required) and MFPC (Management Frame Protection Capable) will be added to the RSN capabilities of the RSN (Robust Security Network) information element to negotiate the ability to protect management frames. The frame format of RSN capabilities is as shown in the figure: when MFPR is set to 1, it indicates that management frame protection is mandatory, while 0 indicates that management frame protection is not mandatory. When MFPC is set to 1, it indicates that management frame protection is supported, while 0 indicates unsupported. When this function is enabled, attackers will not be able to destroy the connection by sending disassociation and deauthentication frames, and protected management frames can effectively resist attacks caused by deauthentication/disassociation frames, providing reliable technical support to secure wireless LAN access and strong identity authentication.
2. If the client does not support the PMF function, the SSID for configuring PMF function cannot be associated with. When the client cannot be associated with the SSID, you can first change the encryption method to WPA2 and configure PMF to Disable, and try client connection again.
3. PMF is supported by Omada EAPs except EAP110-OutdoorV3/V4,EAP115-Bridge V1,EAP110V4,EAP115V5, EAP690E HD V1, EAP225-Wall V2.
Get to know more details of each function and configuration please go to Download Center to download the manual of your product.
Looking for More
Is this faq useful?
Your feedback helps improve this site.
What’s your concern with this article?
- Dissatisfied with product
- Too Complicated
- Confusing Title
- Does not apply to me
- Too Vague
- Other
Thank you
We appreciate your feedback.
Click here to contact TP-Link technical support.
Deze website gebruikt cookies om de gebruikservaring te verbeteren, onlineactiviteiten te analyseren en om gebruikers de best mogelijke ervaring te bieden op onze website. U heeft de mogelijkheid op ieder moment de cookies te weigeren. Bekijk onze privacyverklaring voor meer informatie.
Your Privacy Choices
Deze website gebruikt cookies om de gebruikservaring te verbeteren, onlineactiviteiten te analyseren en om gebruikers de best mogelijke ervaring te bieden op onze website. U heeft de mogelijkheid op ieder moment de cookies te weigeren. Bekijk onze privacyverklaring voor meer informatie.
Standaard Cookies
Deze cookies zijn noodzakelijk voor de werking van de website en kunnen niet worden uitgeschakeld.
TP-Link
SESSION, JSESSIONID, accepted_local_switcher, tp_privacy_banner, tp_privacy_base, tp_privacy_marketing, tp_top-banner, tp_popup-bottom, tp_popup-center, tp_popup-right-middle, tp_popup-right-bottom, tp_productCategoryType
Youtube
id, VISITOR_INFO1_LIVE, LOGIN_INFO, SIDCC, SAPISID, APISID, SSID, SID, YSC, __Secure-1PSID, __Secure-1PAPISID, __Secure-1PSIDCC, __Secure-3PSID, __Secure-3PAPISID, __Secure-3PSIDCC, 1P_JAR, AEC, NID, OTZ
Zendesk
OptanonConsent, __cf_bm, __cfruid, _cfuvid, _help_center_session, _pendo___sg__.<container-id>, _pendo_meta.<container-id>, _pendo_visitorId.<container-id>, _zendesk_authenticated, _zendesk_cookie, _zendesk_session, _zendesk_shared_session, ajs_anonymous_id, cf_clearance
Analyse en Marketing Cookies
Cookies voor analyse geven ons de mogelijkheid uw activiteiten op onze website te volgen en zo de functionaliteit van de website aan te passen en te verbeteren.
Marketing cookies kunnen op onze website worden geplaatst door externe adverteerders waar wij mee samenwerken om een profiel te creëren met uw interesses en u zo van relevante advertenties te kunnen voorzien op andere websites.
Google Analytics & Google Tag Manager
_gid, _ga_<container-id>, _ga, _gat_gtag_<container-id>
Google Ads & DoubleClick
test_cookie, _gcl_au