diff --git a/docs/on_boot_config.md b/docs/on_boot_config.md
index 24a6bcf0..32f54494 100644
--- a/docs/on_boot_config.md
+++ b/docs/on_boot_config.md
@@ -103,10 +103,17 @@ A number of other parameters can be applied in the same way as with Wi-Fi.
Can be followed by several options:
* `WIFI_WPA23=1`
- Allows to connect to mixed WPA2/WPA3 network. Available only on new images >= 2025.03.03.
+ Allows to connect to mixed WPA2/WPA3 networks in WPA2 mode. Specifically,
+ this enables WPA2 PMF (protected management frame) support.
+
+ !!! note
+ Available only on new images >= 2025.03.03.
* `WIFI_HIDDEN=1`
- Allows to connect to hidden Wi-Fi network. Available only on new images >= 2024.03.12.
+ Allows to connect to hidden Wi-Fi network.
+
+ !!! note
+ Available only on new images >= 2024.03.12.
* `WIFI_ADDR=192.168.0.100/24`
`WIFI_DNS=8.8.8.8`
`WIFI_GW=192.168.0.1`
Configures a static IP on the Wifi. Only IPv4 is available here. For IPv6 you'll need to change
diff --git a/docs/wifi.md b/docs/wifi.md
index 81b9b176..0f69aa45 100644
--- a/docs/wifi.md
+++ b/docs/wifi.md
@@ -46,20 +46,28 @@ browser) should also work.
[root@pikvm ~]# chmod 640 /etc/wpa_supplicant/wpa_supplicant-wlan0.conf
```
- !!! note "WPA2 and WPA3 support"
- Add options `key_mgmt=WPA-PSK-SHA256 WPA-PSK` and `ieee80211w=1` to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf`
+ !!! note "Connecting to mixed WPA2/3 networks in WPA2 mode (older devices)"
+ Add options `key_mgmt=WPA-PSK-SHA256 WPA-PSK` and `ieee80211w=1`
+ to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf` inside the `network={` block.
+
+ This enables WPA2 PMF (protected management frame) support, which is
+ often necessary to connect to WPA2/3 mixed mode networks.
!!! note "Using Wi-Fi with hidden ESSID"
- Add option `scan_ssid=1` to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf`
+ Add global option `scan_ssid=1` to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf`
!!! note "Using 5GHz Wi-Fi in the USA"
- Add option `country=US` to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf`
+ Add global option `country=US` to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf`
- !!! note "Block 2ghz or 5ghz"
- Add option `bssid=xx:xx:xx:xx:xx:xx` to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf` within the `network={` block
+ !!! note "Block 2 GHz or 5 GHz"
+ Add option `bssid=xx:xx:xx:xx:xx:xx` to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf`
+ inside the `network={` block.
+
+ Here, `xx:xx:xx:xx:xx:xx` is the MAC address of the specific 2 GHz or 5 GHz
+ AP that you want to _allow_. All other APs in this network will be blocked.
-5. Enable WPA-supplicant service:
+5. Enable the `wpa_supplicant@wlan0` service:
```console
[root@pikvm ~]# systemctl enable wpa_supplicant@wlan0.service