Cisco CCNA (200-301)Network FundamentalsHard

An engineer is reviewing a CAPWAP deployment between lightweight access points and a wireless LAN controller. Which statement accurately describes the CAPWAP tunnel behavior by default?

  1. ABoth control and data traffic are encrypted using DTLS by default.
  2. BControl traffic is encrypted with DTLS, but data traffic encryption is optional.
  3. CNeither control nor data traffic is encrypted unless manually configured.
  4. DData traffic is always encrypted, but control traffic is sent in cleartext.
Show answer & explanation

Correct answer: B. Control traffic is encrypted with DTLS, but data traffic encryption is optional.

CAPWAP establishes two separate tunnels between the AP and WLC: a control channel, which is encrypted with DTLS by default to protect management traffic, and a data channel, whose DTLS encryption must be explicitly enabled (often for security-sensitive deployments) since it adds processing overhead.

Why the other options are wrong

  • A. Data traffic encryption is not enabled by default; it must be configured separately.
  • C. Control traffic is encrypted by default, so this is incorrect.
  • D. This reverses the actual default behavior of CAPWAP encryption.

CAPWAP Control and Data Channels

CAPWAP (Control And Provisioning of Wireless Access Points) uses two logical tunnels between AP and WLC: a control channel (always DTLS-encrypted by default) and a data channel (DTLS encryption optional).

  • Control channel: UDP port 5246, DTLS encrypted by default
  • Data channel: UDP port 5247, encryption optional, must be enabled manually
  • Enabling data DTLS increases CPU load on WLC and APs

Memory trick: Control is always locked, Data's lock is optional.

More Network Fundamentals questions