As Wi-Fi networks evolve toward WPA3 and Wi-Fi 7, network operators face a common challenge: supporting advanced security mechanisms while maintaining compatibility with legacy devices.

Many existing devices support only WPA2-PSK, while modern Wi-Fi 7 devices increasingly rely on stronger authentication methods such as SAE and SAE-EXT-KEY. In mixed-device environments, this often forces administrators to choose between stronger security and backward compatibility.

RSN Override (RSNO) and Multiple RSN Override (MRSNO) were introduced to address this challenge.

MRSNO allows an Access Point (AP) to advertise multiple security configurations simultaneously using:

    • Standard RSN IE
    • RSN Element Override
    • RSN Element Override 2

A station (STA) supporting RSN Override can connect using the specific security configuration for which it has been configured.

Legacy STAs are often designed to expect only a single AKM and cipher suite in the RSN information element. When multiple advanced security profiles are advertised together, interoperability issues can occur.

To address this, RSN Override minimizes the standard RSN IE to contain only broadly supported security parameters while advertising advanced security options through separate RSN Override elements.

For example:

    • WPA2-PSK can be advertised in the standard RSN IE.
    • WPA3-SAE can be advertised in RSN Override.
    • SAE-EXT-KEY can be advertised in RSN Override 2.

This enables both legacy and modern clients to connect using the same SSID while maintaining appropriate security levels.

Without RSN Overriding

When an AP advertises only modern security methods such as WPA3, legacy devices may be unable to connect.

RSNO

Legacy client fails to connect when the AP advertises only advanced security mechanisms.

With RSN Overriding

An AP advertises:

    • RSN (Standard)
    • RSN Override
    • RSN Override 2

These represent parallel security profiles under the same SSID.

As a result:

    • Legacy devices use the standard RSN profile.
    • Modern Wi-Fi 7 devices select the appropriate RSN Override profile.
    • Multiple client generations can coexist on a single network.

MRSNO Beacon Advertisement

The beacon frame below shows how an MRSNO-capable AP advertises multiple security profiles simultaneously.

RSNO

Test Objective

The objective of this validation was to verify that an MRSNO-capable AP can simultaneously support:

    • Legacy WPA2-PSK clients.
    • Wi-Fi 7 SLO clients using SAE.
    • Wi-Fi 7 SLO clients using SAE-EXT-KEY.
    • Wi-Fi 7 MLO clients using SAE-EXT-KEY.

while allowing each client to select only the security profile for which it is configured.

Test Setup

Equipment

Device Quantity
MRSNO-Capable Access Point 1
RSNO-Capable Wi-Fi 7 Clients 3
Legacy Wi-Fi Client 1

 

 

RSNO

Test Procedure

The MRSNO AP was configured to advertise:

Security Profile Advertisement Method
PSK Standard RSN IE
SAE RSN Element Override
SAE-EXT-KEY RSN Element Override 2

The following scenarios were executed independently.

Important Notes

  1. A STA connects only using the RSN profile for which it is explicitly configured.
  2. STAs do not automatically select arbitrary RSN profiles.
  3. Non-matching RSN profiles are ignored.

Supported Client Combinations

Legacy Client PSK AP
WiFi 7 SLO STA
with RSNO Capable
SLO STA
PSK/SAE/SAE-EXT-KEY
RSN IE - PSK
RSN Element Override - SAE
RSN Element Override 2 - SAE-EXT-KEY
6G SAE/SAE-EXT-KEY
WiFi 7 MLO STA
with RSNO Capable
MLO STA
SAE-EXT-KEY

Scenario 1: Legacy Client (PSK)

The legacy client was configured with WPA2-PSK credentials and connected to the MRSNO AP.

Since the AP advertises PSK in the standard RSN IE, the legacy client uses the standard RSN information element for association.

Observation

The client successfully associated using the PSK profile advertised in the standard RSN IE.

RSNO

Scenario 2: Wi-Fi 7 SLO Client (SAE)

The Wi-Fi 7 SLO client was configured for SAE authentication.

The AP advertises SAE through the RSN Element Override IE.

Observation

The client successfully selected the SAE security profile and completed association.

RSNO

Scenario 3: Wi-Fi 7 SLO Client (SAE-EXT-KEY)

A second Wi-Fi 7 SLO client was configured for SAE-EXT-KEY authentication.

The AP advertises SAE-EXT-KEY through RSN Element Override 2.

Observation

The client successfully selected the SAE-EXT-KEY profile and completed association.

RSNO

Scenario 4: Wi-Fi 7 MLO Client (SAE-EXT-KEY)

A Wi-Fi 7 MLO client was configured with SAE-EXT-KEY authentication.

The AP advertises SAE-EXT-KEY through RSN Element Override 2.

Observation

The MLO client successfully associated while utilizing the advertised SAE-EXT-KEY security profile.

Test Results Summary

Scenario Security Method Result
Legacy Client PSK Pass
Wi-Fi 7 SLO Client SAE Pass
Wi-Fi 7 SLO Client SAE-EXT-KEY Pass
Wi-Fi 7 MLO Client SAE-EXT-KEY Pass

The results demonstrate that each client correctly selected its configured security profile without interference from other advertised RSN profiles.

RSN Override provides an effective mechanism for balancing security evolution with device compatibility.

By advertising multiple security profiles within a single SSID, MRSNO enables:

    • Backward compatibility for legacy devices.
    • Adoption of stronger WPA3-based security mechanisms.
    • Support for advanced Wi-Fi 7 security modes.
    • Simplified network deployment without maintaining multiple SSIDs.

The validation results confirm that legacy WPA2 clients, Wi-Fi 7 SLO clients, and Wi-Fi 7 MLO clients can successfully coexist and connect using their respective security configurations when MRSNO is implemented.

References:

https://www.intuitibits.com/2025/07/01/balancing-security-and-compatibility-with-rsn-override/

https://mrncciew.com/2025/10/20/wpa3-personal-deployment-options/

Discover more from Alethea Communications Technologies

Subscribe now to keep reading and get access to the full archive.

Continue reading