跳至主要內容

WPA2-Personal 與 WPA2-Enterprise 有何不同?

WPA2-Personal 在所有裝置上共用同一個密碼。WPA2 和 WPA3-Enterprise 則透過 802.1X 對照 RADIUS 伺服器,對每個使用者或裝置進行個別驗證,這正是 SOC 2、ISO 27001 和 PCI DSS 的要求。Purple 在雲端中透過您現有的存取點執行 RADIUS,並自動核發憑證。

Native 802.1X Cloud RADIUS Compatibility Across Hardware & Identity Platforms
Wireless APs:Cisco MerakiHPE ArubaRuckus WirelessJuniper MistUbiquiti UniFiFortinetCambium NetworksExtreme Networks
Identity Providers:Microsoft Entra IDGoogle WorkspaceOktaPing IdentityJumpCloudActive Directory

TL;DR / Key Takeaways

  • WPA2 and WPA3-Enterprise authenticate every user or device individually over 802.1X against a RADIUS server - the required standard for SOC 2, ISO 27001, and PCI DSS compliance.
  • Instead of a single pre-shared key (PSK), each user or device authenticates uniquely, eliminating shared passphrases and preventing lateral network movement.
  • Cloud RADIUS removes legacy Microsoft NPS servers and local Active Directory agents, operating directly via cloud identity providers.
  • Native SCIM integration with Microsoft Entra ID, Okta, and Google Workspace revokes network access immediately when an employee departs.

Personal 與 Enterprise - 選擇適合的模式

WPA 標準有兩種模式。WPA-Personal (WPA2-PSK, WPA3-SAE) 使用單一密碼,供所有加入該 SSID 的使用者共用。這適用於家庭環境。WPA-Enterprise 則透過 802.1X 針對 RADIUS 伺服器單獨驗證每位使用者或每台裝置。對於重視撤銷、稽核或合規性的任何場所,此模式皆為必備。

Security dimensionWPA-個人 (PSK / SAE)WPA-企業 (802.1X)
認證資訊共用密碼每位使用者專屬的憑證、密碼或 iPSK
基礎架構僅需存取點存取點 + RADIUS 伺服器 (或 RADIUS-as-a-Service)
撤銷輪替整個網路的密碼在 IdP 中停用單一使用者
稽核軌跡無 - 所有裝置看起來完全相同每位使用者專屬的工作階段記錄
適用對象家庭、微型單一信任場所辦公室、飯店、校園、體育場,以及任何受監管的場所
Deployment Blueprint

Deploy WPA2 & WPA3-Enterprise 802.1X in 4 simple steps

Eliminate complex on-premises NPS RADIUS hardware and server maintenance. Purple acts as a zero-trust cloud overlay on your existing network hardware.

01Time: ~3 mins

Connect Identity Provider (IdP)

Authorize Purple with your Microsoft Entra ID (Azure AD), Google Workspace, or Okta account via single sign-on (SSO) and SCIM. No local Active Directory agent or domain controller modifications required.

02Time: ~5 mins

Point Wireless APs to Cloud RADIUS

In your Meraki, Aruba, Ruckus, Mist, or UniFi dashboard, enter Purple’s redundant Cloud RADIUS IP addresses, authentication ports (1812/1813), and shared secret for your WPA2/WPA3-Enterprise SSID.

03Time: ~4 mins

Configure 802.1X Auth & EAP Security

Select your preferred authentication protocol: EAP-TLS with automated PKI device certificates or PEAP-MSCHAPv2 with corporate directory credentials. Set fallback policy and VLAN assignments.

04Time: ~3 mins

Automate User Onboarding & SCIM Offboarding

Deploy Passpoint (Hotspot 2.0) or automated WiFi profiles to employee laptops and mobile devices via MDM (Intune, Jamf, Kandji). When an employee leaves, access is automatically revoked in real time.

Looking to migrate from legacy Microsoft NPS or FreeRADIUS servers? Speak with our wireless architecture team

WPA3-Enterprise 與 WPA2-Enterprise 的比較

WPA3 不僅僅是升級版的 WPA2。以下四項變更對企業部署至關重要。

強制伺服器憑證驗證

用戶端在傳送認證資訊前,必須先驗證 RADIUS 伺服器的憑證。這能杜絕困擾配置錯誤之 WPA2-Enterprise 部署的雙面人(evil-twin)攻擊。

受保護的管理訊框 (PMF)

取消驗證與取消關聯訊框皆經過密碼學簽章,因此攻擊者無法再透過偽造的訊框將用戶端踢出網路。

192 位元 Suite B 模式

適用於政府、國防和關鍵基礎設施的選用高安全性模式。全程採用 Suite B 密碼學 - 包含金鑰交換、加密和 MAC。

向下相容性

WPA3-Enterprise 可以在與 WPA2 相同的 SSID 上以過渡模式執行,因此您不需要進行強制切換。較新的用戶端會協商使用 WPA3;較舊的用戶端則會降級使用 WPA2-Enterprise。

Purple 產品的涵蓋範圍

  • 員工 WiFi:針對託管筆記型電腦使用配備 EAP-TLS 的 WPA2/3-Enterprise,針對舊型裝置使用 PEAP。
  • 多租戶 WiFi:在單一 SSID 上使用 iPSK,並將每個租戶隔離在專用區域網路 (Private Area Network) 中。
  • 訪客 WiFi:在公開 SSID 上使用 OpenRoaming/Passpoint,並在適當情況下將 WPA3-Enhanced Open 作為備用方案。
  • 無密碼 WiFi:涵蓋 EAP-TLS、iPSK、Passpoint 和 SAML 的更廣泛中心。
  • RADIUS-as-a-Service:為每次加入請求進行驗證的雲端 RADIUS 引擎。
  • 員工 WiFi 標準:對照專為 IT 領導者設計的銅級、銀級和金級框架,評估您的 WPA-Enterprise 部署成效。

Compare WPA2-Enterprise against a shared PSK to see how the two modes differ on per-user credentials, audit logs, and employee offboarding.

常見問題

WPA2-Personal 與 WPA2-Enterprise 有何不同?

WPA2-Personal 在所有裝置上共用同一個密碼。WPA2 和 WPA3-Enterprise 則透過 802.1X 對照 RADIUS 伺服器,對每個使用者或裝置進行個別驗證,這正是 SOC 2、ISO 27001 和 PCI DSS 的要求。Purple 在雲端中透過您現有的存取點執行 RADIUS,並自動核發憑證。

什麼是 WPA-Enterprise?

WPA-Enterprise 是專為組織設計的 IEEE 802.11 安全模式。與單一共享密碼 (WPA-Personal) 不同,每個使用者或裝置都會透過 802.1X 向 RADIUS 伺服器進行個別驗證,通常使用憑證 (EAP-TLS) 或使用者名稱與密碼 (PEAP)。每個工作階段都會獲得唯一的加密金鑰,且可在不干擾網路其他部分的狀況下,針對個別裝置撤銷存取權限。

WPA2-Enterprise 與 WPA3-Enterprise 有何不同?

WPA3-Enterprise 修正了 WPA2-Enterprise 中已知的弱點。最重要的變更包括:現在強制進行伺服器憑證驗證(封堵了困擾 WPA2 的邪惡雙生仔攻擊管道)、管理訊框受到保護,且選配的 192 位元 Suite B 模式提供了國防級的密碼學保護。WPA3-Enterprise 在過渡模式下與 WPA2-Enterprise 向後相容,因此您可以逐步升級。

802.1X 驗證如何運作?

其中涉及三個對象。請求端(用戶端裝置)要求加入。驗證器(存取點)將用戶端保持在隔離狀態,並將其 EAP 訊息轉發給驗證伺服器 (RADIUS)。RADIUS 伺服器驗證憑證(憑證、密碼或權杖),並指示存取點允許或拒絕。每個成功的工作階段都會獲得一個衍生自該驗證的唯一加密金鑰,因此單一受駭裝置無法解密其他裝置的資料。

什麼是 EAP-TLS?為什麼它是黃金標準?

EAP-TLS 使用具有雙向憑證驗證的 TLS 握手。用戶端使用裝置憑證證明其身分,伺服器使用伺服器憑證證明其身分,且工作階段金鑰是在加密通道內進行交涉。沒有密碼可被網路釣魚或竊取 - 您必須從裝置本身擷取私鑰。對於使用 MDM 的託管裝置,EAP-TLS 是最合適的預設選擇。

我可以在現有的存取點上部署 WPA3-Enterprise 嗎?

2020 年以後推出的大多數企業級存取點都在韌體中支援 WPA3-Enterprise。您通常會在 SSID 上啟用 WPA3-Enterprise,並在過渡期間保留 WPA2 作為備用方案。較舊的 AP 可能僅支援 WPA2-Enterprise - 當這些 AP 與雲端 RADIUS 和 EAP-TLS 搭配使用時仍然安全,因此極少需要進行全面汰換升級。

我需要運行 RADIUS 伺服器才能使用 WPA-Enterprise 嗎?

是的 - WPA-Enterprise 是圍繞外部驗證伺服器定義的,在實務上即指 RADIUS。您可以於內部部署運行(FreeRADIUS、Microsoft NPS、Cisco ISE),或以服務形式採用。Purple RADIUS-as-a-Service 是大多數不想自行營運伺服器的客戶所選擇的雲端託管方案。

部署 WPA2-Enterprise 仍然安全嗎?

是的,只要部署得當。針對 WPA2-Enterprise 的已知攻擊,都需要用戶端設定錯誤(未進行伺服器憑證驗證,而這正是 WPA3 強制要求的),或者需要實體接觸裝置。透過 MDM 強制執行伺服器憑證驗證並使用 EAP-TLS,可消除實際風險。雖然未來仍首選 WPA3-Enterprise,但沒有必要恐慌性地遷移目前正常運作的 WPA2-Enterprise 部署。

我該如何處理不支援 802.1X 的裝置?

有兩個不錯的選擇。第一,iPSK (Identity PSK) 在單一 SSID 上為每台裝置提供唯一的預先共用金鑰 - 具備 WPA-Personal 的使用者體驗,以及 WPA-Enterprise 的單一裝置撤銷功能。第二,MAC 驗證旁路 (MAB) 允許已知的良好 MAC 位址進入受限的 VLAN。Purple 在同一網路上同時支援這兩者以及 WPA2/3-Enterprise。

我可以在不運行自己的 RADIUS 伺服器的情況下部署 WPA2-Enterprise 嗎?

是的,您不需要運行自己的 RADIUS 伺服器。根據定義,WPA2-Enterprise 需要 RADIUS 驗證伺服器,但透過 Purple RADIUS-as-a-Service,該伺服器託管於雲端:您只需將無線基地台指向 Purple,而無需架設 FreeRADIUS、Microsoft NPS 或 Cisco ISE。您仍然可以針對 Entra ID、Okta 或 Google Workspace 獲得支援 EAP-TLS 或 PEAP 的完整 802.1X 驗證,且無需安裝、修補或維護任何本地端驗證硬體的高可用性。

What is the difference between WPA2-Enterprise and WPA3-Enterprise?

WPA2-Enterprise uses 802.1X with CCMP-128 encryption. WPA3-Enterprise introduces mandatory Protected Management Frames (PMF) to prevent deauthentication attacks, supports 192-bit cryptographic suites (CNSA / Suite B), and eliminates obsolete fallback ciphers.

Can I deploy WPA2/WPA3-Enterprise without an on-premises RADIUS server?

Yes. Purple Cloud RADIUS replaces legacy Microsoft NPS and FreeRADIUS servers. Your wireless access points authenticate directly via redundant cloud RADIUS endpoints integrated with Microsoft Entra ID, Okta, or Google Workspace.

How does WPA-Enterprise integrate with Microsoft Entra ID (Azure AD)?

Purple syncs with Entra ID using SCIM and OAuth 2.0. When an employee logs in via 802.1X or a client certificate, RADIUS checks user status and group membership in Entra ID in real time. Disabling an account in Entra ID revokes WiFi access immediately.

Last reviewed:

See how WPA 企業級 works in venues like yours, and how Purple compares to alternatives.