iPad Pro 11 Wi-Fi merges SSIDs with different security types

Ipad pro 11 UI Merges Different SSIDs with different security types into One Network


Hello Experts,


I have a network deployment where we broadcast two SSIDs with the same name:

  • One is an open SSID broadcast on both 2.4 GHz and 5 GHz radios.
  • The other is a WiFi 7-compliant SSID (WPA3 OWE) broadcast on the 6 GHz band.

6 GHz-capable clients, including my Ipad pro 11, should detect both the open SSID and the WPA3 OWE SSID. However, on the Ipad pro 11, the Wi-Fi settings appear to merge these two SSIDs into a single entry, which prevents me from explicitly selecting the WPA3 OWE SSID.

When connected, the device frequently switches between the two SSIDs and does not remain consistently on the WPA3 OWE SSID, making it difficult to fully benefit from WiFi 7 performance.

In contrast, Windows devices do not merge the SSIDs; they display both separately, allowing me to select and stay connected to the WPA3 OWE SSID without issue.

Could anyone clarify if this merging behavior on Ipads and a way to explicitly select the WPA3 OWE SSID on the Ipad pro 11? Any guidance or settings recommendations would be greatly appreciated.


Best Regards,

Adnan

iPad Pro (M5, 2025)

Posted on Mar 2, 2026 12:39 AM

Reply

Similar questions

12 replies

Mar 3, 2026 6:04 AM in response to AdnanWiFi

AdnanWiFi wrote:

Thank you, @MrHoffman.

To clarify, my setup involves broadcasting both Open and WPA3 OWE SSIDs with the same name from the same set of APs—not different APs.


To clarify, IMNSHO, these two networks are misconfigured.


And yes, it is clear you want the behavior provided by Windows here, and which is to further differentiate the conflictingly-named networks by network-specific configuration details.


Most clients don’t and won’t do that differentiation. Apple clients don’t do that.


That Windows makes that differentiation means it also needs to tie those security details or maybe tie the BSSIDs with the credentials too, and network changes probably also mean new passwords need to be saved such as a whole new network such as when WPA3 is selected or a nee AP is brought online, so there are knock-off effects here. (If Windows is tied to the BSSIDs, yuck.)


Options? You can certainly explain to me how Window works here (and Windows is not in my wheelhouse), or you can get rid of the Apple gear and probably some or all of most other Wi-Fi gear and use solely Windows with these same-but-different networks, or you can convince Apple and other vendors to update their Wi-Fi clients to differentiate these co-named-but-disparate networks, or you can use one SSID for internal and one SSID for guests.



PS: before anybody gets too excited about Wi-Fi 7 MLO, approximately nobody fully implements all of MLO (yet?), and most barely implement it. (Details)


Mar 2, 2026 8:47 PM in response to AdnanWiFi

We aren't necessarily experts here, just iPad users trying to help each other understand how to cope with what Apple supplies. In many cases, after a question is asked, some other user will recognize the situation and have some advice to offer, either because they have experienced something similar or based on general information or standard documentation.


Network management was never my specific area of technical expertise, but I did have some training a while ago, and I've read some recent router setup documentation. I'm more familiar with using SSIDs with the same name the way the iPads are interpreting them: usable interchangeably. If networks need to be distinguished by the end devices, it is customary to use different SSID names, often with suffixes indicating the different capabilities.


All of which is to say that the iPad behavior makes more sense to me than the Windows behavior that you report.

Mar 3, 2026 1:58 AM in response to AdnanWiFi

"Appreciate if I get official response from Apple if there exists some limitations on mobile devices/ IPads that prevents this from happening "


Apple don't read these boards. You could contact Apple directly - link at bottom of page - but I doubt if you'll get a response much different from Mr Hoffman's.


I also don't really understand why you think it's not working. Apple devices choose the best signal based on a number of factors - interference, noise, signal strength, etc. So if an iDevice switches from the WiFi 7 signal to a different one it's because the different one has better connection, irrespective of the benefits of WiFi 7. As a user it would be very annoying if my iPhone sat on a poor WiFi signal and required me to manually try all the other WiFi bands to find a better one. Sounds to me it's working as it should.

Mar 3, 2026 9:54 AM in response to MrHoffman

The SSIDs in question are an Open SSID (no encryption or authentication) and a WPA3 OWE SSID (Opportunistic Wireless Encryption, which provides encryption without requiring authentication or a password). Both are broadcast from the same physical access point (AP), typically using separate virtual interfaces (each with its own BSSID). Since neither SSID requires authentication, devices do not prompt for credentials when connecting.


Windows does not tie connections to BSSIDs in its user interface, instead it primarily displays networks by SSID. As a result, these two SSIDs usually appear as distinct entries in the Windows Wi-Fi list  one labeled as the Open network and the other as the WPA3 OWE network even though they originate from the same AP. This separation in the UI is helpful, as it lets users clearly choose the more secure WPA3 OWE option.



If a client (ipad OS in this case) were to merge or fail to distinguish these SSIDs properly (treating them as variants of the same network), it could increase vulnerability to SSID confusion attacks such as those exploiting CVE-2023-52424. This can enable man-in-the-middle attacks, security downgrades, traffic interception….


I still feel Windows in more optimal in differentiating the distinct networks. Please correct me why you feel otherwise.

Mar 3, 2026 1:20 PM in response to AdnanWiFi

I would not implement what Microsoft developers did here, nor would I design Wi-Fi networks this way.


For those folks directly implementing Wi-Fi clients, I would consider implementing a security-downgrade notification for existing and known networks in addition to any existing insecure-networks warnings, but would not (by default) implement Wi-Fi security upgrade notifications. These notifications and potentially these connection prohibitions possibly tailorable with added MDM and endpoint security apps installed on (secured) clients.


But... What I think of this hilariously hacked-together pile of ill-considered design choices is irrelevant, nor is what I might implement differently relevant here, same as what I might think about the equally inadvisable squatting-in-.local DNS setups that Microsoft was also once and unwisely recommending and is accordingly still in widespread and lingering customer implementations.


It is what it is.


Options?

  • Prohibit the use of Apple gear and probably also prohibit some or all of the other Wi-Fi gear in existence, and use solely Windows on these same-but-different Wi-Fi networks.
  • Convince Apple and most other Wi-Fi client vendors to follow Microsoft to update their Wi-Fi clients to differentiate these networks. (This quite possibly also adding confusion and messes when upgrading existing Wi-Fi security to better WPA3 or WPA-next security, too.) (Product Feedback)
  • Reconfigure these networks into disparate SSIDs for guests and for secure access, and into broader Wi-Fi client compatibility. This might include deploying profiles and/or QR codes for network access, potentially adding VLANs and VPN bridging and related network remediation and network upgrades.


Of these options, fixing the original bad design is probably the least bad and seemingly most likely to happen within in my lifetime, and this possibly combined with deploying newer APs, switching, and gateways. Maybe add RADIUS or such as a means to better control access to the more "trusted" Wi-Fi networks originating from Entra or AD or Open Directory or whatever the customer is using as their directory.



Mar 3, 2026 12:01 AM in response to MrHoffman

Thank you, @MrHoffman.


To clarify, my setup involves broadcasting both Open and WPA3 OWE SSIDs with the same name from the same set of APs—not different APs.


This configuration is required for a mall environment that has recently upgraded its WLAN infrastructure to WiFi 7. The goal is for visitors with WiFi 7-capable devices to connect to the WPA3 OWE SSID, which is broadcast only on the 6GHz radio, allowing them to benefit from the enhanced capabilities of WiFi 7. Meanwhile, legacy devices that are not WiFi 6E/7 compliant should connect to the Open SSID, which is available on the 2.4GHz and 5GHz radios.


The customer operates multiple malls in the city, many of which have not yet been upgraded to WiFi 7. To provide seamless connectivity for users roaming between malls, the same SSID name is used for both the WPA3 OWE and Open networks. This approach ensures that visitors who have completed captive portal authentication in any mall can maintain connectivity as they move between locations.


I have seamless experience when testing this with windows endpoints as in their UI they are successfully able to distinguish these two SSID as distinct and lists as two entries under Wi-Fi. Once I opt to associate on WPA3 OWE SSID, it seamlessly remain connected on WiFi 7.


However my Ipad pro 11 fails to distinguish it as unique SSIDs and rather shows it as one, thus not leaving me with an option to select to associate with either WPA3 OWE or Open SSID. Also it keeps hopping between these two SSIDs.


Appreciate if I get official response from Apple if there exists some limitations on mobile devices/ IPads that prevents this from happening

Mar 3, 2026 1:43 AM in response to MrHoffman

Thank you, @MrHoffman.


To clarify, my setup involves broadcasting both Open and WPA3 OWE SSIDs with the same name from the same set of APs—not different APs.


This configuration is required for a mall environment that has recently upgraded its WLAN infrastructure to WiFi 7. The goal is for visitors with WiFi 7-capable devices to connect to the WPA3 OWE SSID, which is broadcast only on the 6GHz radio, allowing them to benefit from the enhanced capabilities of WiFi 7. Meanwhile, legacy devices that are not WiFi 6E/7 compliant should connect to the Open SSID, which is available on the 2.4GHz and 5GHz radios.


The customer operates multiple malls in the city, many of which have not yet been upgraded to WiFi 7. To provide seamless connectivity for users roaming between malls, the same SSID name is used for both the WPA3 OWE and Open networks. This approach ensures that visitors who have completed captive portal authentication in any mall can maintain connectivity as they move between locations.


I have seamless experience when testing this with windows endpoints as in their UI they are successfully able to distinguish these two SSID as distinct and lists as two entries under Wi-Fi. Once I opt to associate on WPA3 OWE SSID, it seamlessly remain connected on WiFi 7.


However my Ipad pro 11 fails to distinguish it as unique SSIDs and rather shows it as one, thus not leaving me with an option to select to associate with either WPA3 OWE or Open SSID. Also it keeps hopping between these two SSIDs.


Appreciate if I get official response from Apple if there exists some limitations on mobile devices/ IPads that prevents this from happening

Mar 3, 2026 10:12 AM in response to AdnanWiFi

It's irrelevant what any of us thinks and whether one is better than the other. Apple devices will continue to work as Mr Hoffman has carefully described unless/until Apple changes them. You can give feedback to Apple, of course, but nothing will change in the near term.


Your points about security might be valid but unless you are going to prevent Apple-device users from accessing your networks then the fact that you recognise the risk possibly puts the onus on you to deal with it, especially if you're doing this in a professional capacity.

Mar 2, 2026 9:34 PM in response to AdnanWiFi

The network designer here has created a version of a Wi-Fi Pineapple attack, which is hilarious.


The resulting behavior of disparate networks sharing SSID and password network design is indeterminate, and different clients and different client versions can behave differently. In most cases, each client will go for the strongest signal absent features such as band steering or such, though the selection criteria can be client-specific. All as you have already observed.


Options? Create a guest network with a dedicated SSID broadcast by your gear, either an open Wi-Fi network or probably better closed with some QR codes to ease connection credentials for the guests or such, and create a second and more secure network with a different SSID. Probably set up VLANs to separate the guest and secure networks.

Mar 2, 2026 9:39 PM in response to markwmsn

Thank you Mark for your response.


If a device does not differentiate between SSIDs with identical names but different security mechanisms, it is more likely to be affected by SSID confusion attacks, similar those described in CVE-2023-52424. In this regard, Windows’ approach displaying them as separate SSIDs is noticeably more robust compared to what I have observed on the iPad Pro 11 as atleast the end user has an option to select from the UI and be aware of existence of two SSIDs.


Is there any documented limitation for mobile devices or iPads regarding this behavior, where the UI merges the SSIDs into a single entry and the device may inadvertently switch between them? Displaying them as distinct SSIDs would allow users to make an informed and secure choice.

Mar 2, 2026 10:17 PM in response to AdnanWiFi

Many clients are going to roam to the strongest signal, and it won’t be seamless.


As for the official answer from Apple, your configuration is not going to be reliable:



Searches for “same ssid different networks” find others that have discovered this doesn’t work, too:


https://robots.net/tech/what-happens-if-you-have-two-routers-with-the-same-ssid/


https://www.snbforums.com/threads/what-happens-when-you-set-2-different-routers-with-the-same-ssid.82762/



Again: One SSID for guests possibly with a separate VLAN, and a second SSID possibly with a separate VLAN and with RADIUS as appropriate.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

iPad Pro 11 Wi-Fi merges SSIDs with different security types

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.