FT PSK Adaptive for WPA2 Personal Roaming

Optimize client roaming
Answer Correct answer: A — Enable FT PSK and set Fast Transition to Adaptive for the Scanning SSID to support both iPads and legacy scanners.

A customer has two Cisco WLCs configured in a SSO cluster. The wireless network supports a large warehouse. The customer purchases new iPads to replace legacy scanners. Both devices connect to a single SSID named Scanning by using WPA2 Personal. The customer wants to use a standards-based method for fast roaming on the new iPads. Which approach meets the scanner requirement and still supports the legacy scanners?

  1. Enable FT PSK and set Fast Transition to Adaptive for the Scanning SSID. Correct Answer
  2. Enable FT 802.1X and set Fast Transition to Adaptive for the Scanning SSID.
  3. Enable optimized roaming globally and enable FT 802.1X on the Scanning SSID.
  4. Enable optimized roaming globally and enable FT PSK on the Scanning SSID.

Community Insight

WPA2 Personal requires FT PSK for fast roaming, and Adaptive mode allows legacy non-802.11r clients to successfully associate alongside FT-capable clients.

This page resolves how to configure standards-based fast roaming for new iPads on a WPA2 Personal SSID while maintaining support for legacy scanners. It establishes that enabling FT PSK with Fast Transition set to Adaptive is the correct approach.

Choosing FT 802.1X because it sounds more secure, ignoring that WPA2 Personal explicitly uses PSK and does not support 802.1X authentication.

Community Discussion (3 comments)

Farhad123 👍 1
802.1X is typically used in WPA2 Enterprise networks, where each device authenticates individually through a RADIUS server. Since the SSID "Scanning" is using WPA2 Personal, enabling FT 802.1X would not be compatible with the existing security setup.
Farhad123 👍 2
A is correct
Lakshan__97 👍 3
here is auth method is PSK , and answer shoudl be FT , and Adaptive makes legacy devices to work

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The SSID uses WPA2 Personal, which relies on a Pre-Shared Key (PSK) rather than 802.1X/EAP authentication. Therefore, Fast Transition (FT) must be configured as FT PSK to match the authentication method. Setting Fast Transition to Adaptive allows 802.11r-capable clients, like the new iPads, to use fast roaming while permitting legacy clients that do not support 802.11r to still associate normally.

Why the Other Options Are Wrong

Options B and C suggest enabling FT 802.1X, which is incompatible with WPA2 Personal and requires a RADIUS server for WPA2 Enterprise. Option D suggests enabling optimized roaming globally, which is a Cisco proprietary feature that forces roaming based on signal thresholds rather than providing a standards-based fast transition method, and lacks the Adaptive setting needed for legacy client support.

Community Comment Notes

Commenters correctly pointed out that the "auth method is PSK", making FT 802.1X incompatible. As Farhad123 noted, "802.1X is typically used in WPA2 Enterprise networks". Another user highlighted that "Adaptive makes legacy devices to work", which is the exact reason Adaptive mode is required over standard Enable mode.

Official Reference

Exam Strategy

Identify the authentication method (PSK vs 802.1X) to determine the FT type, then check if legacy clients exist to decide between Enable and Adaptive mode for Fast Transition.

Related Analysis

← Back to 300-425 Study Guide