As Wi-Fi networks evolve toward WPA3 and Wi-Fi 7, network operators face a common challenge: supporting advanced security mechanisms while maintaining compatibility with legacy devices.
Many existing devices support only WPA2-PSK, while modern Wi-Fi 7 devices increasingly rely on stronger authentication methods such as SAE and SAE-EXT-KEY. In mixed-device environments, this often forces administrators to choose between stronger security and backward compatibility.
RSN Override (RSNO) and Multiple RSN Override (MRSNO) were introduced to address this challenge.
MRSNO allows an Access Point (AP) to advertise multiple security configurations simultaneously using:
-
- Standard RSN IE
- RSN Element Override
- RSN Element Override 2
A station (STA) supporting RSN Override can connect using the specific security configuration for which it has been configured.
Legacy STAs are often designed to expect only a single AKM and cipher suite in the RSN information element. When multiple advanced security profiles are advertised together, interoperability issues can occur.
To address this, RSN Override minimizes the standard RSN IE to contain only broadly supported security parameters while advertising advanced security options through separate RSN Override elements.
For example:
-
- WPA2-PSK can be advertised in the standard RSN IE.
- WPA3-SAE can be advertised in RSN Override.
- SAE-EXT-KEY can be advertised in RSN Override 2.
This enables both legacy and modern clients to connect using the same SSID while maintaining appropriate security levels.
Without RSN Overriding
When an AP advertises only modern security methods such as WPA3, legacy devices may be unable to connect.

Legacy client fails to connect when the AP advertises only advanced security mechanisms.
With RSN Overriding
An AP advertises:
-
- RSN (Standard)
- RSN Override
- RSN Override 2
These represent parallel security profiles under the same SSID.
As a result:
-
- Legacy devices use the standard RSN profile.
- Modern Wi-Fi 7 devices select the appropriate RSN Override profile.
- Multiple client generations can coexist on a single network.
MRSNO Beacon Advertisement
The beacon frame below shows how an MRSNO-capable AP advertises multiple security profiles simultaneously.

Test Objective
The objective of this validation was to verify that an MRSNO-capable AP can simultaneously support:
-
- Legacy WPA2-PSK clients.
- Wi-Fi 7 SLO clients using SAE.
- Wi-Fi 7 SLO clients using SAE-EXT-KEY.
- Wi-Fi 7 MLO clients using SAE-EXT-KEY.
while allowing each client to select only the security profile for which it is configured.
Test Setup
Equipment
| Device | Quantity |
|---|---|
| MRSNO-Capable Access Point | 1 |
| RSNO-Capable Wi-Fi 7 Clients | 3 |
| Legacy Wi-Fi Client | 1 |

Test Procedure
The MRSNO AP was configured to advertise:
| Security Profile | Advertisement Method |
|---|---|
| PSK | Standard RSN IE |
| SAE | RSN Element Override |
| SAE-EXT-KEY | RSN Element Override 2 |
The following scenarios were executed independently.
Important Notes
- A STA connects only using the RSN profile for which it is explicitly configured.
- STAs do not automatically select arbitrary RSN profiles.
- Non-matching RSN profiles are ignored.
Supported Client Combinations
| Legacy Client | PSK | AP |
|---|---|---|
|
WiFi 7 SLO STA with RSNO Capable |
SLO STA
PSK/SAE/SAE-EXT-KEY
|
RSN IE
- PSK
RSN Element Override
- SAE
RSN Element Override 2
- SAE-EXT-KEY
|
| 6G | SAE/SAE-EXT-KEY | |
|
WiFi 7 MLO STA with RSNO Capable |
MLO STA | |
| SAE-EXT-KEY |
Scenario 1: Legacy Client (PSK)
The legacy client was configured with WPA2-PSK credentials and connected to the MRSNO AP.
Since the AP advertises PSK in the standard RSN IE, the legacy client uses the standard RSN information element for association.
Observation
The client successfully associated using the PSK profile advertised in the standard RSN IE.

Scenario 2: Wi-Fi 7 SLO Client (SAE)
The Wi-Fi 7 SLO client was configured for SAE authentication.
The AP advertises SAE through the RSN Element Override IE.
Observation
The client successfully selected the SAE security profile and completed association.

Scenario 3: Wi-Fi 7 SLO Client (SAE-EXT-KEY)
A second Wi-Fi 7 SLO client was configured for SAE-EXT-KEY authentication.
The AP advertises SAE-EXT-KEY through RSN Element Override 2.
Observation
The client successfully selected the SAE-EXT-KEY profile and completed association.

Scenario 4: Wi-Fi 7 MLO Client (SAE-EXT-KEY)
A Wi-Fi 7 MLO client was configured with SAE-EXT-KEY authentication.
The AP advertises SAE-EXT-KEY through RSN Element Override 2.
Observation
The MLO client successfully associated while utilizing the advertised SAE-EXT-KEY security profile.
Test Results Summary
| Scenario | Security Method | Result |
|---|---|---|
| Legacy Client | PSK | Pass |
| Wi-Fi 7 SLO Client | SAE | Pass |
| Wi-Fi 7 SLO Client | SAE-EXT-KEY | Pass |
| Wi-Fi 7 MLO Client | SAE-EXT-KEY | Pass |
The results demonstrate that each client correctly selected its configured security profile without interference from other advertised RSN profiles.
RSN Override provides an effective mechanism for balancing security evolution with device compatibility.
By advertising multiple security profiles within a single SSID, MRSNO enables:
-
- Backward compatibility for legacy devices.
- Adoption of stronger WPA3-based security mechanisms.
- Support for advanced Wi-Fi 7 security modes.
- Simplified network deployment without maintaining multiple SSIDs.
The validation results confirm that legacy WPA2 clients, Wi-Fi 7 SLO clients, and Wi-Fi 7 MLO clients can successfully coexist and connect using their respective security configurations when MRSNO is implemented.
References:
https://www.intuitibits.com/2025/07/01/balancing-security-and-compatibility-with-rsn-override/
https://mrncciew.com/2025/10/20/wpa3-personal-deployment-options/



