Cisco CCNA (200-301)Network FundamentalsHard
An engineer is reviewing a CAPWAP deployment between lightweight access points and a wireless LAN controller. Which statement accurately describes the CAPWAP tunnel behavior by default?
- ABoth control and data traffic are encrypted using DTLS by default.
- BControl traffic is encrypted with DTLS, but data traffic encryption is optional.
- CNeither control nor data traffic is encrypted unless manually configured.
- DData traffic is always encrypted, but control traffic is sent in cleartext.
Show answer & explanationAnswer & explanation
Correct answer: B. Control traffic is encrypted with DTLS, but data traffic encryption is optional.
CAPWAP establishes two separate tunnels between the AP and WLC: a control channel, which is encrypted with DTLS by default to protect management traffic, and a data channel, whose DTLS encryption must be explicitly enabled (often for security-sensitive deployments) since it adds processing overhead.
Why the other options are wrong
- A. Data traffic encryption is not enabled by default; it must be configured separately.
- C. Control traffic is encrypted by default, so this is incorrect.
- D. This reverses the actual default behavior of CAPWAP encryption.
CAPWAP Control and Data Channels
CAPWAP (Control And Provisioning of Wireless Access Points) uses two logical tunnels between AP and WLC: a control channel (always DTLS-encrypted by default) and a data channel (DTLS encryption optional).
- Control channel: UDP port 5246, DTLS encrypted by default
- Data channel: UDP port 5247, encryption optional, must be enabled manually
- Enabling data DTLS increases CPU load on WLC and APs
Memory trick: Control is always locked, Data's lock is optional.