wpa-psk ascii <key>
Set the SSID's WPA2 passphrase. Every station must join with exactly the same key; it is case-sensitive.
Example
AP-Lobby(config-ssid)# wpa-psk ascii LobbyGuest2026Here wpa-psk alone already turns WPA2 on; real IOS also needs 'authentication key-management wpa version 2', so always type both. The SSID and the passphrase are one word each here, because the station's join takes one token for each. A station with the wrong key never associates and its pings fail. Real WPA2 wants a passphrase of 8 to 63 characters, so use one that long here too.
Don't just read it — type wpa-psk ascii <key> in a real network simulator in your browser and watch it take effect. No install, no account needed to start.
Frequently asked
What does the "wpa-psk ascii <key>" command do?
Set the SSID's WPA2 passphrase. Every station must join with exactly the same key; it is case-sensitive.
What's the common gotcha with "wpa-psk ascii <key>"?
Here wpa-psk alone already turns WPA2 on; real IOS also needs 'authentication key-management wpa version 2', so always type both. The SSID and the passphrase are one word each here, because the station's join takes one token for each. A station with the wrong key never associates and its pings fail. Real WPA2 wants a passphrase of 8 to 63 characters, so use one that long here too.
Example of "wpa-psk ascii <key>"
AP-Lobby(config-ssid)# wpa-psk ascii LobbyGuest2026