ExamOpsPractice free

Cisco Certified Network Associate (CCNA) 200-301 · Free study guide

Objective 5.10 — Configure a WPA2-PSK WLAN

A WPA2 pre-shared-key WLAN requires more than typing a network name and secret. The controller must bind an enabled WLAN or profile to the intended SSID, select WPA2 personal security with AES-based protection, map clients to the correct network, and provide a key that authorized clients can use. Field names vary by interface, so follow the relationships rather than memorizing one screen.

Map the GUI objects

The administrative profile name helps operators identify the configuration; the SSID is the name clients discover. These values may match, but they serve different audiences. A WLAN identifier or policy profile can connect the SSID to security, VLAN, QoS, and forwarding behavior. Enabling the object publishes it only where the associated access points and policy allow.

Select WPA2 personal or PSK authentication and an appropriate AES-based protection option. Avoid legacy compatibility settings unless a documented client requirement and migration plan justify them. Enter a long, unique pre-shared key and handle it as a secret—never place a live key in screenshots, tickets, training examples, or source control.

Connect access to the correct VLAN

Successful wireless authentication does not guarantee DHCP or application reachability. The policy must map clients to the intended VLAN or interface, and the controller and switch path must carry that network. DHCP, DNS, gateway, ACL, and routing services remain downstream dependencies.

QoS and advanced client settings should follow application requirements. A high-priority label does not create bandwidth, and changing several advanced options at once makes fault isolation harder. Begin from documented defaults and change only what the design requires.

GUI configuration and verification map

Controller labels differ between software generations, so locate these relationships rather than memorizing coordinates from one screenshot.

Worked scenario

Clients can see Workshop-Staff and accept its pre-shared key, but they receive no IPv4 lease. Authentication logs show success. The SSID is mapped to VLAN 30, while the controller uplink allows only VLANs 10 and 20. The wireless security configuration is functioning; the wired path is incomplete. Add the approved VLAN to the correct trunk path, verify DHCP reachability, and retest one client before broad rollout.

Use a disciplined sequence

Create the WLAN identity, set the SSID, select the security generation and personal authentication, choose the protection suite, enter the secret, map the policy or interface, review QoS and advanced settings, and enable the WLAN. Record the intended values without recording the secret itself. Plan a rollback for existing users before changing a production WLAN.

Verification evidence

Test discovery, association, authentication, address assignment, default gateway, DNS, and an authorized application. Review controller client state, access-point join and policy state, VLAN mapping, wired trunk allowance, DHCP leases, and denial evidence from a deliberately incorrect key. Confirm the SSID is available only where intended.

Common traps

Readiness checklist

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free