Cisco Certified Network Associate (CCNA) 200-301 · Free study guide
Objective 5.10 — Configure a WPA2-PSK WLAN
A WPA2 pre-shared-key WLAN requires more than typing a network name and secret. The controller must bind an enabled WLAN or profile to the intended SSID, select WPA2 personal security with AES-based protection, map clients to the correct network, and provide a key that authorized clients can use. Field names vary by interface, so follow the relationships rather than memorizing one screen.
Map the GUI objects
The administrative profile name helps operators identify the configuration; the SSID is the name clients discover. These values may match, but they serve different audiences. A WLAN identifier or policy profile can connect the SSID to security, VLAN, QoS, and forwarding behavior. Enabling the object publishes it only where the associated access points and policy allow.
Select WPA2 personal or PSK authentication and an appropriate AES-based protection option. Avoid legacy compatibility settings unless a documented client requirement and migration plan justify them. Enter a long, unique pre-shared key and handle it as a secret—never place a live key in screenshots, tickets, training examples, or source control.
Connect access to the correct VLAN
Successful wireless authentication does not guarantee DHCP or application reachability. The policy must map clients to the intended VLAN or interface, and the controller and switch path must carry that network. DHCP, DNS, gateway, ACL, and routing services remain downstream dependencies.
QoS and advanced client settings should follow application requirements. A high-priority label does not create bandwidth, and changing several advanced options at once makes fault isolation harder. Begin from documented defaults and change only what the design requires.
GUI configuration and verification map
- Create or select the WLAN profile, set the client-facing SSID, bind the intended policy profile or interface, and enable it only for the approved AP scope.
- Select WPA2 personal or PSK authentication with the platform's AES or CCMP protection option. Enter a long training-only PSK through the secret field; never record a live value in a screenshot or exported lab file.
- Map the client policy to the intended VLAN and verify that the controller uplink and downstream switches carry that VLAN to DHCP and its gateway.
- In the controller client view, confirm association, WPA2 authentication, policy and VLAN assignment, address lease, and session state. Then test one deliberately incorrect training key and both an allowed and denied network path.
Controller labels differ between software generations, so locate these relationships rather than memorizing coordinates from one screenshot.
Worked scenario
Clients can see Workshop-Staff and accept its pre-shared key, but they receive no IPv4 lease. Authentication logs show success. The SSID is mapped to VLAN 30, while the controller uplink allows only VLANs 10 and 20. The wireless security configuration is functioning; the wired path is incomplete. Add the approved VLAN to the correct trunk path, verify DHCP reachability, and retest one client before broad rollout.
Use a disciplined sequence
Create the WLAN identity, set the SSID, select the security generation and personal authentication, choose the protection suite, enter the secret, map the policy or interface, review QoS and advanced settings, and enable the WLAN. Record the intended values without recording the secret itself. Plan a rollback for existing users before changing a production WLAN.
Verification evidence
Test discovery, association, authentication, address assignment, default gateway, DNS, and an authorized application. Review controller client state, access-point join and policy state, VLAN mapping, wired trunk allowance, DHCP leases, and denial evidence from a deliberately incorrect key. Confirm the SSID is available only where intended.
Common traps
- Confusing an internal profile name with the broadcast SSID.
- Selecting WPA2 but leaving an unintended legacy protection option.
- Exposing the pre-shared key in documentation.
- Stopping after successful association without testing DHCP and policy.
- Forgetting the controller-to-switch VLAN path.
Readiness checklist
- I can trace SSID, WLAN, policy, security, and VLAN mappings.
- I can identify WPA2 personal and AES-oriented settings.
- I protect the pre-shared key throughout its lifecycle.
- I verify the full client path after authentication.
Practice and apply this objective
A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.
Start practicing free