Exploring the Power and Security of Wi-Fi 7 with Cisco
Discover how Cisco is unlocking the full potential of Wi-Fi 7 – delivering faster speeds, lower latency and rock-solid reliability. In this session, we explore how Cisco combines cutting-edge performance with enterprise grade security to power the next generation of wireless connectivity. Don’t miss what’s next in wireless innovation.
Presented by Matthew Landry, VP Product Management, Nicholas Swiatecki, Product Manager, Anand Gurumurthy, Technical Marketing Engineer, and Stephen Orr, Distinguished Engineer. Recorded live at Mobility Field Day 13 in Santa Clara, CA on May 7, 2025. Watch the entire presentation at https://techfieldday.com/appearance/cisco-presents-at-mobility-field-day-13/ or visit https://techfieldday.com/event/mfd13/ or https://Cisco.com for more information.
Transcript
Hello everyone. My name is Matt Landry, uh, and I have the distinct privilege and pleasure of leading the Cisco Wireless organization. And, uh, and I wanna thank you all, whether you're here in person or tuning in remotely.
Thank you for for joining us today and allowing us the time to talk to you and tell you about some of the great things we've been working on. We have a lot of content for a lot of folks from the team. And in an extreme example of irony, they put together a slide for me that is content free because I am the senior leader for the organization.
So of course I'm primarily content free, but I'm really proud of the team because we're gonna be talking a lot about wifi seven, which is really the point that we've reached after years of effort to bring together our product portfolios in wireless. For many years we've had our Arrow net turned Catalyst wireless portfolio. We've had our Meraki wireless portfolio with wifi six E.
We started to bring those together. But with wifi seven, it's here one Cisco Wireless product line. We don't think in terms of Meraki or Catalyst, we don't design with that in mind.
We think about how to deliver a single Cisco wireless product line. And this is the pattern that we are following at, at Cisco Networking overall, right? We have delivered a single set of wifi seven hardware we call common hardware that can be deployed with on-premises or cloud managed models.
We have developed a common set of licensing so that people don't have to think about, do I need a license that, so that I can run this in a locally managed model, or do I need some, some Meraki cloud licenses? That, that too is in the past with wifi seven and Cisco Wireless common licensing, common support model for them both. And we're bringing our management platforms together to deliver a single experience for managing and operating networks.
And this is spreading across Cisco networking. This is what we are doing with switching. This is what we're doing with routing and SD wan.
This is the path that we are on. And Cisco Wireless, as often as is the case with wireless, is leading the way on implementing these changes. So I'm very, very proud of what the team has done here.
And hopefully you'll notice that we have changed the way that we think and talk about about wireless. So with, with that, I want to just, just comment on, you know, what is wireless the team focused on? And then hand it off to the folks who can really go into some detail.
And, and that is amongst all of this bringing together of our management models for networking and wireless specifically, we're focused on three primary areas. We're focused on seamless mobility, we're focused on deep security on wireless, and of course building technology that enables you to build the most reliable and self-reliant networks that you can with wireless. And you'll see examples of this in everything we talk about today.
How are we delivering in these areas? And this is where we're investing. This is what we can focus on now that we don't have to think about.
Is it a catalyst solution or a rocky solution? This is the focus for our Cisco wireless team. So with that, I want to hand it off to Nicholas UND and Steven or if he's still out there and we got the video sorted out so that we can jump into some much more interesting discussion than, than my content free wireless at a glance.
So we'll be talking about the, uh, exploring the power and security of wifi seven. Nicholas, please take it away. Uh, my name is n Teke, joined here with Anand and, uh, the omnipresence Stephen Orr in the room, uh, remotely.
In the next kind of 30 minutes or so, we're gonna talk about the power and security of wifi seven. It's gonna be a bit of an atypical, uh, presentation. 'cause normally I'll be blabbering on for 30 minutes, but I'm probably only gonna take five to seven minutes.
And I'm gonna hand it off to Anand who's gonna talk about how do we actually implement wifi seven, the design challenges, WPA three, all of these interesting things that we've seen, the observations from client base. And we're gonna go through all of that lovely data. Um, 'cause we know you guys love it.
And yes, we, we brought toys as well. Come on. It's Cisco Cisco's presentation.
We had some hardware. No way. Now, as Matt kind of alluded to and dovetailing off of that, something we've been working very hard on is meeting our customers where they are.
And this, we're still fully committed to this. Now, one of the things we like to do here at Mobility Field Day is show up with a slide and say, we're gonna do this and we're gonna check in six months later and say, Hey, yeah, we're still doing it. Here's how we're doing it.
And now, you know what, two years later show up and say, yeah, we did it. Right? So for everything Cisco Wireless, everything, wifi seven doesn't matter if you want to be fully cloud enabled, if you want to be fully on-prem in a mine somewhere under some security clients or if you want to be hybrid in between, right?
The big focus area of us taking these on-prem installations, connecting to the cloud where it makes possible. So this is absolutely still a focus area and we're pretty happy how far it's come so far. Great.
Now, and of course if there's questions, you know, you guys will shout out. So another slide we introduced, Keith will remember, 'cause I remember him nodding. I wanna say two years ago was this kind of, so where are we?
Slide, we started with six C. Now we have an updated version with seven. And what I would argue, what we would argue is we're right here.
We're right here in the chasm of early adopters and kind of the early majority. And the reason why I want to say we're here is all the reasons and all the, the data that Anon is gonna present, right? We still have some challenges with WPA three.
There's still a few client operating systems that don't have all full support for wifi seven and some security modes. There is one major hardware vendor out there that doesn't have a laptop yet with wifi seven. And once we get all that, I'm sure we're gonna pass it.
So again, coming back to something we presented two years ago, 18 months ago, 12 months ago, this is where we believe we are now. I hope you all agree. If you don't, I'm sure I'm gonna hear about it on, on X or blue sky.
That's kind of where we see the world right now. And of course kind of consumer wifi seven, that's raced on, you know, you get a camp, uh, gateway from a an ISP. You got wifi seven there.
So let's talk about what we're doing for wifi seven. As I mentioned, no Cisco presentation without hardware. Um, I brought a few toys.
These were announced at Cisco Live in Europe a few months ago. I don't know if y'all had a chance to see them. Uh, Royal, you can kind of pass that around.
And Sam Sam's pass this around. That's, so these are the 72 I and the 72 H, right? I'm gonna put this on the table.
These are our newest introduction to the family, kind of the two by two tier of access points, tri van concurrent, uh, products that we're super proud about. I'm gonna go into details in just a moment. Um, but before I do that, I do want to acknowledge the D one.
When we built wifi six E, we were the first that put an integrated direction antenna and then quote unquote indoor access point. We believed there was a great way to solve low power indoor for six gigahertz. We still believe that's a great idea, which is why we have a wifi seven model.
And the idea was so good that we saw other vendors copying it. So to those guys, thank you. 'cause it really validated the idea.
Thanks for everybody who implemented anyways. Um, oh, and as Matt kind of alluded to, all these are global use aps. We don't have regulatory domains anymore.
We don't think about Meraki or Catalyst. You plug them in, they figure out where they need to be in the world and, and how they should operate. I think everybody here is past that.
Sorry, Uh, it's called D one and not just D because we're gonna have D 2D three. So the question is why is it D one? Yeah, is there gonna be a D two?
Um, I get this question a lot. We did it kind of in, uh, into the 60 generation we call the D one. So we wanted to keep that lineage and, um, for kind of, is there a D two?
What happens? Hold, hold your question and I'll address that a little later. Anyways, diving into kind of the details of this, uh, the de two new aps, um, a few key high allies.
I'm not gonna read out all the specs, speeds and feeds, but for the 72 I, which of course replaces the 62 i, it has one party trick that I wanna make sure everybody here in the room sees. So I put a big arrow, this is Tri Bandt three radio concurrent, but it also has a party trick. It has what we internally call MR 44 mode.
So if you have an environment where you don't care about six gigahertz, maybe you can't implement the security standards, maybe you have a cost conscious customer, this access point can actually transform to run in a two by two plus four by four mode on the five gig band. So we know they're placed in the world that don't have six gig. So this access point actually covers not just the, Hey, I'm a tri band two by two access point, but also covers, uh, other use cases and other deployment scenarios.
Um, and this is something we're, we're extremely proud of on the H side, tri band concurrent. And I say this because you cannot take it at for a given for wall plate access points anymore these days that you have all three bands. Concurrent Sam is smiling, he knows what I'm referring to.
Um, he called out on this is yes, we have 15 watts p oe out. So yes, you can still power phones, cameras, what have you. Uh, if you wanna do that, you're gonna give it more than 30 watts in and we'll give you 15 watts out.
Finally, as always, same brackets, we give our engineering teams an arguably very, very hard time to say you must be backwards compatible with your brackets. So 72 i, that's our normal bracket, one and two you've had for kind of Cisco installations for roof 15 years or so. But on the H side, we've taken a step further.
It does not matter if you're coming from say, a 9 1 0 5 W on the catalyst side bracket or a Meraki 36 H. This access point works with both brackets, so just makes it easier for you to refresh, uh, installs out there from a physical perspective. I'm just gonna hold here for a second to see if there's any immediate questions.
If not, I'll, I'll move on. But, you know, I'll just take a little sip of water here. You also saw me put here on the desk.
The, uh, the desk mount for it is something we do wanna call out. It's being much requested in the past. We know a lot of you like to deploy these aps for small pop-up locations.
Put it on a desk, plug some, some laptops into it for a remote or a fast deployment. We absolutely support that. And hey, we have the kind of accessories to go with it.
You know what, Royal, you can pass that around if you don't mind. Nick, go ahead. Did you find much difference in the heat dissipation when it's in one form or Another?
So the question is, did we find a lot of challenges like, or differences in heat dissipation, vertical versus horizontal? Yes. That's why it's that way.
Great question. Anyways, so what's next? Um, kind of the most exciting and most boring slide, stay tuned for Cisco Live.
Um, we like new toys, but for that you'll have to stay tuned for Cisco Live. And with that, Anand, uh, is gonna come on stage and give us a lot of information about how to deploy with wifi seven and the challenges and the latest from the client ecosystem. Uh, very quick control about me.
I'm Anan and I'm a senior technical leader, technical marketing focused on the wifi products and solutions. My primary focus is on the access point platforms. I work very closely with Nicholas and other product managers.
Uh, we work together a lot. So if you see one of us, the other one is in very far behind. We are like the Y and in wifi.
So together we boost the signal stent and also double the channel with. So, um, with that quick intro and that wifi plan, let me get into the, the session. So if my, uh, memory serves correct, it was exactly near back spring 2024, MFT 11 where we first started talking about, uh, wifi seven.
I still remember the awesome presentation that Nicholas made, um, where he talked about the enterprise readiness of wifi seven. We have come a long way since then. Uh, this year, 2025 especially, has been super busy, uh, with the multiple access point platforms that we rolled out the lab trails.
And the proof of concept is all, uh, going very well, and the deployment is also gaining momentum. So what I wanna do, uh, in this session for the say next 15, 20 minutes or so, is to share with you the learnings, observations, the tips and tricks. Um, you know, uh, that will definitely help the, you know, the folks who are deploying wifi seven and also for all those lab trails.
So with that, the very first topic that I want to touch upon is the wifi seven client support, the availability in the market and its readiness. The, the entire, the client landscape. I'm sure you all agree with me, that, uh, uh, uh, a rich and a stable wifi, uh, client ecosystem is absolutely necessary for the successful adoption of any wifi generation or standard.
And wifi seven is no exception there. So in the first in this category is the Android. In fact, it was one of the first wires to support wifi seven.
We use all those Samsung S 20 fours and the Google pixels to try out wifi seven in the very, very early days. Um, we have a very rich set of client there. So all good there.
The next in this categories, the iPhone. Uh, we had a surprise, uh, from Apple last fall with, uh, the support of wifi seven in their, uh, iPhone 16 and 16 pro. This kind of really got the market.
I mean, the wifi community exited, so I still remember seeing so many LinkedIn posts and the expos people showing off their iPhone 16 pro and, and the interop with the wifi seven access points and the Multilink corporations and their observations and so on. The iPhone 16 E, which was introduced a couple of months back, don't seem to support wifi seven. Uh, they have restricted the capability to just wifi clicks.
They don't even seem to have the support for, uh, wifi 60. The third in this category is an important one. Windows, uh, wifi seven personal, it's available in Windows, uh, 11, uh, 24 H two.
The public, uh, the version, the software that's available, the Windows laptops are predominantly based on the Intel and the Qualcomm chip sets off late. We are seeing, uh, uh, media tech chip sets also with the Windows laptops, uh, wifi seven for enterprise. It's not available in the public version of, uh, windows seven.
It's available in the dev channel. The can builds and the dev beta, uh, built, uh, for folks who are trying out those de builds, you might have noticed that the wifi is of an enterprise. You're able to form the connection to the access point, but it doesn't successfully roam.
There are roaming issues. Um, you know, it does a full lot. Microsoft has recently fixed the issue and we got a confirmation.
And the specific bill numbers is, uh, listed in the slide. So if you want go give a try, please to, uh, use these bill numbers to see the roaming work in, uh, with those wifis of an enterprise. Of course, the last in the category is the, the Mac and iPad voice.
We still don't have support. Hopefully we'll hear some good news from Apple very soon. And, um, as you see, right, I mean the client ecosystem is still evolving, but when you, like about eight months back, we have come a long way.
And I'm sure the next time when we, uh, meet for the MFT, we are gonna talk about a, a much larger, uh, client set. So have a question for you guys. Uh, what do you think is the coolest feature in wifi?
Seven? Any guesses? Uh, and it takes the number.
What do you see? Seven MLO? I say m of course, IMLO.
So your good, uh, guess is as good as mine. Um, when I, when I initially read through this, the wifi seven specs, the features, when I, um, read about MLOI was immediately convinced that this is gonna be the most ex exiting feature in wifi seven. But I was, I was convinced, but I want to be super assured.
So I thought, uh, let me turn out to this person. This, uh, brainy, intelligent, uh, very trustworthy, always gives an neutral, unbiased answer. So, um, I turned out to chat G so I asked Chad G, Hey, what do you think is the coolest feature in wifi?
Right? So, and I post all sort of tricky questions. You know, chat G was so consistent, it gave an anonymous answer always that MLO is the feature, right?
Why am I picking this topic today? So I've been front-ending this wifi seven activities. Um, you know, the, I'm frontend the beta trials with the five platforms or so we've launched and, uh, engaged in several customer conversations, the events, and so on that three questions that we get on wifi, a certain topic.
First one is on MLO, how things work, their observations and, you know, question centered around all the MLO methods and so on. Second one is on the wifi a and security with all the con confusion happening around the, the WPA three, the new acas and whatnot. And the third one is on, um, the p requirements on the platform.
Um, I've never seen anyone asking about the 4K qualms or the three 20 mega channel with and things like that. Either it's too easy a feature, you know, people take it for granted or people don't care about it. I don't know, but I'm not, uh, I mean, I've not, I've been, I was never asked a single question on those features.
So, uh, of course, uh, I'm not gonna deep dive into all the methods of MLO. I'm pretty sure you're all aware of the different methods of MLO. Um, MLO is, uh, of course, uh, is Multilink Corporation, where the access points and the clients use multiple bands to, uh, you know, uh, simultaneously exchange, uh, data traffic.
And as per the wifi alliance picks, right, there are these three methods that the access point SAP implement, the MLSR and MLSR for a single radio and the M-L-M-R-S-D-R for the multiple radio and for the clients, they have to do the MLSR and either the E-M-L-S-R or the M-L-M-R-S-D-R, The two popular ml, uh, MLO methods or E-M-L-S-R and M-L-M-R-S-D-R. And when you compare these two, uh, uh, methods, the popular methods, E-M-L-S-R and mlr, M-L-M-R-S-D-R, there are pros and cons to each of these methods. With MLMR, SST R because of its multi radio capability, obviously you get a better throughput when compared to EML sr, but EM lsr slightly easy on the, the battery on power.
Uh, so, uh, the earlier implementations of EML sr, from our observations, what we have noticed is it seemed to be, uh, proofing a symmetric channel bit. It's not from all the vendors, but some of the vendors, what we have seen. So it needs, like say, uh, if the MLO link is on the five and the six ER spans, it needed like 40 plus 40 or 80 plus 80 if it's what it was, an ASYMETIC channel width.
So, uh, it wasn't doing an MLO, it was doing a single link cooperation. 4 and six. So we get an incremental throughput just because of the 20 mega channel edition.
But I have to call out this Qualcomm Fast Connect, 7,800 high band, simultaneous. They implement dual five gig guides or a five plus, uh, six gig guides. So we observed almost like close to two x of throughput that you get with a single link.
So there's a misconception that, you know, people think that, you know, moment they turn on MLO, they're gonna get like an awesome throughput, two X of throughput, but it's not the devil is in the detail. Uh, whether it's E-M-L-S-R or MLMR, how does the MLMR work? 4 and a five?
And, uh, if it's the E-M-L-S-R, is it a older driver as a newer driver? You know? So there are lots of details here.
So I thought I'll share this details. So, uh, folks who are trying out MLO don't expect a magic throughput increase. Uh, definitely you'll see a throughput improvement and some latency improvements Before you move on.
Have you done any MLO testing with punctured channels? Uh, Or you got something punctured in six as part of an MLO link? Yes, we have done the testing, but uh, testing I can share with you the detail.
I mean the data. But we have done internal testing with all those combinations of, uh, you know, an MO happening puncturing, introducing, yeah, we have done those testing. Okay, yeah, Love to see that.
So, uh, this is, uh, we take, we have done a lot of testing internally. Of course, we took the, the popular clients out there and the different wifi seven features and, uh, you know, what works and what are the limitations and so on. The couple of things that I wanna call out, I always, uh, apple phones do not support three 20 megahertz yet.
4 and a five. Um, but, uh, they do an E-M-L-S-R if the SSA is broadcasted just on the 5 1 6 garand. So if you look at all the other vendors, they do either E-M-L-S-R or M-L-M-R-S-D-R Google picks, uh, does things, uh, slightly differently.
Moving on to the next important topic on the wifi seven security. Um, this is, uh, I mean this, a recap of the wifi seven security requirements, uh, like wifi six C, WIFI seven has, uh, mandated the need for WP three. It's minimal and it's needed for certifications and operation.
There are new games that been added, uh, SA extension key and FTSC extension key that translates 24 and 25. There are also enhanced cipher requirements for OW and, uh, WP three personnel. And we also need, uh, uh, PMFS mandate.
So this table kind of lists all the different generations of wifi and all the, the security requirements here. WP three is something not new. Uh, it's not like, uh, just, uh, that's been happening just last couple of years.
It was needed. It was a, it was mandated and was needed for wifi six certification. And, um, PMF was happening even prior to that.
PF has been there for many years now. I don't even, uh, remember the year when was first introduced. The key difference difference between wifi seven and wifi six C is the enhanced cipher requirements on the word WE and the enhanced a KM, uh, you know, the new a KM editions on the WP three personal and also the new Cipher Edition.
As far as the enterprise is concerned, it's exactly the same. So there's no difference there. So the early days, uh, uh, it was a very relaxed implementation from what we have seen, like, uh, it was the, the client vendors were not strictly following the standards.
They can, um, they can, they can work just with an A CE or even very, very earlier dev builds. We have seen WPA two PSK, uh, work with the kind of a wifi seven. So, uh, it was a very relaxed implementation from the client side.
So what we did on the infrastructure side, we also want to be relaxed and because to allow all the clients, we didn't want to put the restrictions. Um, but going forward, you're going to enforce a very, uh, you know, we're going to enforce this requirements very strictly just follow the specs. And we also seeing the clients also adhering to the, the standards.
So, um, and it's gonna be a very strict enforcement if you try out, now, there are chances you might see, uh, WP three with the SAE just work find with wifi seven and mlo another question. It's a simple question, but I do get this question, uh, because of all this WP three commend, some people think that maybe the wifi seven aps cannot broadcast, uh, uh, you know, know w land with the lower security. Yes, it can.
4 and a fike guard span and its capability is restricted to 11 a x. It cannot connect to the six ki guard span. It cannot get the 11 B rates and the MO.
So in instead of backwards compatibility, what's the, what's the talk track on forward compatibility with wifi six E platforms that need to run GCMP 2 56 or roaming? I'm gonna cover that. Okay?
I do please hang in there for a few minutes. Yep. I'm gonna touch upon that.
So yeah, I've been reminded that I have only five more minutes, but I have a lot more slides to cover, but I'm just gonna go fresh through stuff. And, uh, uh, so with, with all this new WP three ments, what, uh, uh, uh, what are the options do we have? How do we go about designing our wlans?
You know, these are all the Cisco's recommendations. Plus what we call is an all in option where you go migrate all your WLANS to it, your WP three network or OW network. So, um, it's, it's gonna make your networks very secure, but is it a practical one?
No, not a practical one, because there are gonna be many clients that's gonna be standard out there. The second one is what we call as the multiple SSA option. You leave your existing SSA such and create new SSA with the new, uh, security requirements for the wifi 60 and wifi seven, eight.
It's very flexible, but it just an additional overhead involved in terms of maintaining the, both on the infrastructure side as well as on the client side. The third one is what we call as an one SSI where, and, uh, some clients are very particular about the branding of the SSID name, like a classic example is. So, um, they want support the legacy clients with the legacy security as well as the newer clients with the newer security, it's absolutely possible.
Uh, we use this, uh, uh, transition mode, so the mix and mode to achieve the same. And, um, as I mentioned, the wifi AP seven AP scan broadcast, SID with the lower, uh, security just cannot connect to six gas span and 11, uh, no 11 B rates and MLO. So how do you go about this?
Option three, which is the most conservative option, you employ the mix and more select the ciphers as, um, um, uh, a is and, uh, GCP 2 56 if it's personal, and select a cams, P-S-K-S-E-S-E, extension key, and all this FT counterparts. So, um, everyone is gonna be happy. Uh, you know, the WPA two clients can connect the wifi six and wifi six C clients capable of doing WP three can connect with the C and wifi seven clients can do with the SE extension key.
So very, very similar concept on the enterprise side as well. Um, go back, Come, Yep. This dialogue box uhhuh is, is right, all of the VARI eight kms and, and check boxes and whatever mm-hmm.
Is, is like a bazooka and looks nothing like the way Meraki has implemented wifi security or frankly, any of your competitors. WW why does this exist? Like why, why, why does, why doesn't this look like everybody else's?
Hey, you want wifi seven? Yes or no? Like, this feels overly complicated to the nth degree.
So, uh, the wireless land control, the idea behind this, we have so many knobs, just this knobs, like we want to give every single knob that you can. But if, if you are played around with recent code, uh, when you, when you select the, the, the a KMS or the ciphers there is this the popup that we put in red color? Oh, I know.
And you have to chase the red alerts all over as you're trying to figure out which boxes to push. It's, it's, it's awful. So not no offense, but was, wasn't sure if you had any commentary on why this didn't look more Meraki like, Uh, Especially with the convergence Feedback taken, but we'll, we'll think about it and then see what, what is the best that we can, uh, we can, we can do here.
I, so, so I, I am curious on that because I was, I was kind of scratching my head on the same thing. You have a box for fast transition. Thank you.
Um, then under your AKs, you also have your FT akm. So if you enable fast transition, does that automatically check the f uh, the FT box for your a kms? Good question.
The actual implementations, no, we do not enable automatically. Okay. We just enable them and then you choose what you want to do.
Okay, so let's say in this WP two, WP three case, right? So maybe I don't want to do FTSA, but I want to do FTSA extension key. So I just wanna check mark that I don't enable all the default FT options out there.
You know, it's just that we have given all the knobs and then you pick and choose what you want. Okay? Yeah.
one x, uh, one question. Like, you know, so we have, we have made use of this transition modes and the mixing modes, uh, uh, to achieve, to take care of the lower security, the, the legacy clients and the newer clients. But, uh, the question is about can I do the same thing with OWE transition?
Uh, no, you cannot. The specs clearly cost of that. You cannot use OWE transition for the six key span and wifi seven.
4 and the five giger spans, right? You have to use on WWE in case you wanna use a six gig GT span or the wifi seven. It's not something Cisco is doing anything special here, the specs.
And if you take the wireless land controller today, we have given the flexibility, but going forward, you're gonna be, uh, super strict and we are going to restrict what you can do with the OW transition. So there are a few, uh, client joint behaviors, how works and so on. But it's straightforward.
But in the interest of time, what I'm gonna do is I'm just gonna, uh, skip a couple of slides and then get into the roaming question that Sam was, uh, asking about. This is a wifi seven client home behavior. I'm taking an example of a personal, the wlan uh, profile is a WP three personal and the A came what we call a configured as say extension key and the cipher as both a years and the G CMP two physics.
Let's say there's a wifi seven client that initially joins with the GCP 2 56. It can do a seamless room to a wifi 60 ap. And we have back ported these new AKs on the WI five 60 aps and our wifi 60 aps can support GCP two as well.
So it's gonna be a seamless room. How far back is that, uh, in platforms? Is that supported As far as the ACAMS are concerned?
You can go all the way till your wave two aps, wave two, yeah, but C ciphers, uh, it kind of, uh, mix it in, uh, the wifi six platform, some wifi six, six platforms do GCP 2, 3 6, some do not do because of underlying chip set. So it is, uh, can I do a seamless room with wifi six? Yes.
Uh, as long as they can matches in the cipher matches. And the next one is there's a wifi six, uh, AP that cannot do a GCP 2 3 6. And it can do only AEs if the wireless client initially joined with AEs, right?
It can do a seamless room. But if you're joined with a GCM P 2 3 6, it cannot do a seamless room. It has to disconnect and rejoin a very similar, um, What's happening.
Ah, yeah. So just a second. Ab I tested this in the lab.
Yes, I've absolutely tested this in the lab. And uh, it just, the proof of the y shark capture where I roamed a wifi seven client starting from a wifi seven AP to a wifi six ap, the 91 30 AP to be very, uh, precise. And there is some red boxes that have marked there just to show the nitty integrities in terms of what marketers it uses because of the MLO functionality.
Uh, but those are all the, the details and, uh, very similar, uh, behavior with, uh, WiFi's, uh, client room behavior with WWE and then with enterprise life is easy. It's supposed to be a seamless room. You have Lots of data from your cloud of clients.
Uh, Uhhuh, do you have any data showing how in the real world with real clients how effective this is? Does it actually do what it's planned? Uh, yo or Nicholas or someone like can I take your help?
Um, in terms of, I, I wanna take your help here. So there's a question here. Sure Thing.
So the question is about, uh, Since you have all the cloud data of lots and lots of clients, millions of them, are they actually doing this wifi seven client roaming behavior? Really good question. We're looking into it.
And then we discovered something. I'm be honest, a little interesting. I dunno if the camera see me, what's the Rome?
Because you know, as we in the past saw Romes as being on a band, and then there's another band and how do you measure Romes? So we're enhancing our data pipelines real right now to give us the right answer. 'cause you know, if you just look at, it was a one band, now it's another band.
Well, with MLO, it's not really a Rome, it's a, you know, but Even, even pre MLO, you should have pre m Oh yeah. And, and pre MLO with roaming analytics, right? We, we have that in in dashboard today, right?
So we have that data and we, we show it. But with MLO it got a little more funky. That's all I'm saying.
Oh, you, You I have it for my customer. You have it for all customers. Yep.
So I, I was asking more of a broader question. Are you finding clients to be, are wifi seven clients more sticky on six? Do they like six more?
Are wifi six e clients better or worse than wifi seven clients? So the short answer, and I just saw Taja do the whole hands thing in the background, it depends on the client type. Generally we've seen Apple being a little nicer than six gig depending on the software version.
'cause I know when we started testing internally, there was a lot of staying away from six gig almost. And we called up a few people and said, what's going on here? Right?
And as the software version that the driver version had gone, we've seen the balancing towards six and like being, being a lot better. So I mean, the old classic, Hey, update your drivers still very much holds true for kind of being non-sick. Um, even more so now, If I heard it correctly, Tony, saying that we have five more minutes, so I, if you have any questions, we can take more questions.
Otherwise, I mean, can we go back and dig into roaming because it feels like there's a lot there to unpack. Yep. You wanna go enterprise or you wanna go OWEI?
Well, I mean, I think that, that, I think what I'm interested in is understanding where the pitfalls are from an, from an industry perspective, right? Mm-hmm. When, when I'm sitting in front of a client doing this, what scenario are they gonna end up and where they're moving clients throughout their facility and, and how is it gonna break and when is it gonna break?
Does this lead to any particular deployment guidelines as far as like salt and peppering of aps or keeping 'em together or roam boundaries, or don't even bother trying until you're all wifi seven. Like what's the practical upshot of this? Because we all know what, how do we fix it for customers who are trying to adopt wifi seven?
Now Let me, uh, give you this answer. This entire, the wifi seven, right? The journey is evolving.
Plus we are so focused on just the basic connectivity, making sure the, the MLO works. And we have clients, uh, today that cannot do enterprise rooming in wifi seven. And you talked about the wifi, uh, what do you call the, the laptop, the Windows laptops, right?
So we have gotten it to a point where the lab level, right on the testing I am, I've ensured that I can do roaming. We just figuring out this like onion peeling effort that's happening. We are planning to come up with such a kind of, what do you call a, uh, a deployment guide and you know, the best practices and whatnot, what is going there?
Give us some time, we'll get there. But we are trying to ensure we are having brainstorming and then looking up at all the possible scenarios. What should work, what should not, what will, I mean what all should work, right?
We are working on that and uh, we are getting there today. There are issues, even just some basic roaming, uh, we are, we are trying to target those issues, but we'll get there with a proper kind of a decent guide. Hey, hey, just real quick, Sam, uh, it's Steven, just a question for you.
Um, so when you talk about roaming I, and just to be a little bit fanan on this, are you talking about cross a cam roaming or are you talking about uh, No, cross a cam roaming? Yeah. Okay.
Problematic. Yes. Yeah, Yeah.
So, so when the slide to non has a, here, this isn't cross a cam roaming, right? This is renegotiation of cipher suites during the roam. So if I was going from wifi six six E, which is, uh, using a ES or GCMP to a wifi seven MLO, all I'm doing at that point is renegotiating the CIP suites.
Uh, if I were going from wifi six E to wifi seven MLO in an enterprise scenario, again, same thing. All I'm renegotiating is the cyber suites. Cyber suites.
Yeah. If it was SAE, I'd actually have to renegotiate the actual 8:00 AM because it's eight km 24. So that, that's where some of the friction might be, and depending upon how the station handles that cross eight KM, uh, movement going forward.
But that, and that's really station dependent. And, and it's SAE dependent, it, it's, it's SAE is what's afflicted here. Uh, right, because it's a different, so in wifi six, six E, it's a KM eight, and then we have the new a kms in wifi seven.
So that, that's the, the challenge you cannot use and, and I'll use this terminology, EHT and MLO. So enhanced throughput data rates are extremely high throughput data rates and multilink operation are synonymous. You, you, everybody uses 'EM interchangeably.
So you cannot have an E-H-T-M-L-O connection without a KM 24 for, uh, SAE, Right? But you can have a, um, you can have a wifi seven connection that's non MLO, Uh, and uh, no, a wifi seven connection would be defined by either extremely high throughput or M-L-O-M-L-O. So you cannot use extremely high put, uh, extremely high through, uh, data rates Without having an ml.
Without having Ml, yeah, okay. With without the right, the correct K. Okay.
So the packet capture what I have is exactly like, I wanna prove the, uh, the idea that, you know, as long as this ACAMS role, uh, implemented as access point, the early generation access point, it's gonna be a seamless room, which is what we have done, like implementing the SEE extension key, right? Yeah. So, uh, we have taken ex taken an example of GCP 2 56 where I can demonstrate a successful room.
Yep. Right? So, uh, if the client, uh, as if the early generation access point, if I do not implement the, the new extension keys, then there is definitely, obviously as, uh, Steve and I mentioned, we are gonna have a problem in roaming.
Well, and, and it brings up a, a ton of deployment scenarios where I feel like if you have, you know, legacy sites with legacy controllers, with mobility groups built between the new controllers or wifi five aps or even older, right? None of that stuff's gonna work well, right? Basically no roaming from old generation into new generation and back and forth, right?
Not, not graceful, it It, well non graceful seven because like if you do ft um, well, anything with Shaw one has also been, um, removed from wifi seven connections. 1 x, um, using SHA one, you couldn't have it in the same roaming mobility domain. So you, you have to be careful of which, uh, again, this is across all vendors, right?
Like when, when building these roaming domains, knowing which a cams, which AP support. Hey, Steven, since you're here. Yeah.
Quick question is, uh, actually, I guess Sam asked us, and then JD said something about it with the, the view from one of, one of the slides that had all of the knobs and the buttons with the different, um, akm, uh, several slides back. Um, and the question was, why, why would you manually configure some of that? And I feel like we, we have two ends of the spectrum right now where products either don't show you what they're doing and you have no clue unless you look at it over the air or you have a bunch of knobs, and then a lot of people don't know what all the different knobs do.
What, what is your view or Cisco's view on the decisions you're making as to when, when those are exposed? Yeah, so it's a great question, jj. I think it is always a work in progress that there's always a balance between the right amount of security and the right amount of, uh, operational simplicity.
And, you know, sometimes in our case, maybe a Rosetta Stone do actually figure out what, what you wanna, what you want to configure. Um, and I also think there's a little bit around the mental model of how do, how do I get from what I'm thinking about to what, uh, what operational model I want without being a cryptographer. So, uh, it, it, again, it's a work in progress.
We we're striking a balance between all the capabilities between, uh, when we have a dashboard we have in Catalyst Center and on-prem on controllers. So, uh, point taken, um, yes, I think we could do, uh, a little bit better there. And that's also what we're trying to do in industry as well, is, uh, help end users or network operators when you make selections, make the selections consistent so that you don't kind of get yourself in a bind or create these roaming issues or create, um, you know, security issues that you're unaware of or unintended consequences.
Yeah, because I mean, I know that sounds like an niche issue question, but it, it impacts so much of whether a client can connect at all and whether it can move and participate in the rest of the network. Thank.