Home > Wireless LAN > Encryption and Authentication > Setting a WPA Encryption Mode

Setting a WPA Encryption Mode

By default, SSIDs on Cisco Meraki access points that are configured as WPA2 will utilize AES encryption.

Mixed Encryption with MR Access Points

Wireless beacons and probe responses will advertise AES as the encryption method for unicast traffic and TKIP as the encryption method for multicast/broadcast traffic. This can be seen in the tagged parameters portion of beacon and probe response management frames in the "RSN Information" element.

Setting the Encryption Type

The WPA encryption setting is SSID specific, and can be found on the Wireless > Configure > Access control page as seen below:


This drop down will allow for "WPA2 only" or "WPA1 and WPA2". The "WPA1 and WPA2" option sets the SSID to perform in mixed mode. The "WPA2 only" option forces AES encryption.


If the device does not support AES, it is also possible to force TKIP only. Please contact Cisco Meraki support to configure this option.

Last modified



This page has no classifications.

Explore the Product

Click to Learn More

Article ID

ID: 1667

Explore Meraki

You can find out more about Cisco Meraki on our main site, including information on products, contacting sales and finding a vendor.

Explore Meraki

Contact Support

Most questions can be answered by reviewing our documentation, but if you need more help, Cisco Meraki Support is ready to work with you.

Open a Case

Ask the Community

In the Meraki Community, you can keep track of the latest announcements, find answers provided by fellow Meraki users and ask questions of your own.

Visit the Community