Skip to content
 
2025-07-23
Latest
Basic Setup of a Cisco Catalyst 9800-CL
The need for better Floor Plans
The need for better Hotel Wi-Fi
WPA3-192-bit mode
When a Block Cipher is not a Block Cipher

Karstens Cyber-Fi Blog

Thoughts on Cybersecurity, Wi-Fi and some other stuff

  • About / Impressum
  • Datenschutzerklärung
  • About / Impressum
  • Datenschutzerklärung
Categories : Cisco VMware Wireless WirelessTags : 9800-CLCisco CatalystESXLeave a comment

Basic Setup of a Cisco Catalyst 9800-CL

On 2025-07-122025-07-12 By Karsten

There are many guides on the internet for the setup of the Cisco Catalyst 9800-CL. But most of them are pretty old, and things have changed in the meantime. This guide is based on version 17.15.3 of the 9800-CL. It shows how to do the basic setup on VMware ESXi

continue reading
Categories : WirelessTags : Floor PlanWi-FiWLANWLAN SurveyLeave a comment

The need for better Floor Plans

On 2025-06-232025-07-12 By Karsten

This post is kind of a sequel to the previous post The need for better Hotel Wi-Fi. Whenever you do a wireless survey, you need a floor plan. If you don’t have one, Ekahau users have the luxury of doing a Just-Go survey, where the floor plan is dynamically generated

continue reading
Categories : WirelessTags : Bad-FiWi-FiWLAN1 Comment

The need for better Hotel Wi-Fi

On 2025-06-202025-06-20 By Karsten

Yes, I am one of the people who enter a building and look up to spot the Access-Points. As a wireless engineer you can: And sometimes a 3) turns into a 1) “Ahh, that’s the reason; now it makes sense!” And part of this crazy notion is to evaluate the

continue reading
Categories : WirelessTags : CNSAEAP-TLSIEEE 802.11RADIUSSuite-B-192Wi-Fi AllianceWLAN KlassentreffenWLPCWPA3WPA3-192Leave a comment

WPA3-192-bit mode

On 2024-11-032024-11-03 By Karsten

This year, I presented the topic WPA3-192-bit mode at the WLAN Klassentreffen (in German) and WLPC in Prague as a 10Talk. This is the video recording from WLPC: Here is the presentation from WLPC 2024 in Prague: And the German version from the WLAN Klassentreffen 2024 in Hamburg: Some more

continue reading
Categories : CWNP WirelessTags : AESCCMPCTRCWSPESPIEEE 802.11IPSecRFC 3610RFC 4303Leave a comment

When a Block Cipher is not a Block Cipher

On 2024-09-152024-09-15 By Karsten

Well, of course a Block cipher is always a Block cipher. But sometimes it might not be used as expected and this can cause some misunderstanding of how things work. If you implement IPsec VPNs, you likely know ESP, the Encapsulating Security Payload and it’s packet format: The Encapsulating Security

continue reading
Categories : WirelessTags : BYODHome OfficeMPSK1 Comment

Reverse BYOD

On 2024-08-152024-08-15 By Karsten

This blog post is for the paranoids among us Many companies use BYOD (Bring Your Own Device) processes to securely connect personal devices to the enterprise network. Typically, Enterprise Authentication with EAP-TLS ensures a good user experience without any struggles when Domain credentials are changed. But how do we connect

continue reading
Categories : WirelessTags : UbiquityWiFiManWiFiMan WizardLeave a comment

The Ubiquity WiFiMan Wizard

On 2024-07-212024-08-13 By Karsten

“Why did no one tell me before???” This July, I visited the Wi-Co (Wireless Community) event in Manchester and learned about a device that ideally fits my use case. Problem Statement When traveling, in meeting rooms, or in hotel rooms, I not only look above me to spot the APs,

continue reading
Categories : Wireless WirelessTags : 9800 WLCWPA3WPA3 Transition DisableLeave a comment

WPA3 Transition Disable

On 2024-03-202024-03-29 By Karsten

Transition Disable is a mechanism to protect a WPA3 network against downgrade attacks and is described in Chapter 8 of the WPA3 Specification 3.3. When this feature is enabled, a station should configure it’s network profile to not connect to the SSID with AKMs that are not allowed in WPA3-only

continue reading
Categories : Cisco General Meraki SecurityTags : Meraki MX5 Comments

Connecting the Meraki MX to the Internet

On 2024-02-192024-02-19 By Karsten

In a previous blog post, I described connecting the Meraki MX to the internal network. In this blog post, I go through different ways to connect to the internet. The internal connection is not detailed here; this is independent of the external connection to the ISP. Option 1: One MX,

continue reading
Categories : Cisco Security Wireless WirelessTags : c9800DACLISERADIUSLeave a comment

Downloadable ACLs with Cisco ISE

On 2024-02-032024-09-15 By Karsten

On the Cisco ISE, we can use Downloadable ACLs (DACLs) as an enforcement method to control what our endpoints are allowed to do in the network. These DACLs can be used with Catalyst switches and also with the Catalyst 9800 WLC starting with version 17.10.1 Compared to named ACLs, the

continue reading

Posts navigation

Older posts

Recent Posts

  • Basic Setup of a Cisco Catalyst 9800-CL
  • The need for better Floor Plans
  • The need for better Hotel Wi-Fi
  • WPA3-192-bit mode
  • When a Block Cipher is not a Block Cipher

Recent Comments

  • Karsten Iwen on Connecting the Meraki MX to the Internet
  • Raymond on Connecting the Meraki MX to the Internet
  • The need for better Floor Plans – Karstens Cyber-Fi Blog on The need for better Hotel Wi-Fi
  • Adrian Garcia on Connecting the Meraki MX to the Internet
  • Karsten Iwen on How to connect the Meraki MX to MS switches

Archives

Categories

  • Allgemeines
  • Apple Macintosh
  • books
  • Certification
  • Cisco
  • CWNP
  • General
  • IoT
  • iPhone / iPad
  • Linux
  • Meinungen
  • Meraki
  • Networking
  • QoS
  • Security
  • Security
  • Training
  • VMware
  • Wireless
  • Wireless

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Karsten is on:

Copyright © All right reserved. | Theme: Newslite by eVisionThemes