12.4_CAPWAP Operation Flashcards
__is an IEEE standard protocol that enables a WLC to manage multiple APs and WLAN
CAPWAP
__: also responsible for the encapsulation and forwarding of WLAN client traffic between an AP and a WLC.
CAPWAP
CAPWAP is based on LWAPP but adds additional security with ____ (DTLS)
Datagram Transport Layer Security
CAPWAP establishes___ on User Datagram Protocol (UDP) ports. CAPWAP can operate either over IPv4 or IPv6, as shown in the figure, but uses IPv4 by default.
tunnels
IPv4 and IPv6 both use UDP ports __ and __.
5246
5247
Port ___is for CAPWAP control messages used by the WLC to manage the AP
5246
Port ___ is used by CAPWAP to encapsulate data packets traveling to and from wireless clients.
5247
However, CAPWAP tunnels use different IP protocols in the packet header. IPv4 uses IP protocol___and IPv6 uses IP protocol ___.
17
136
A key component of CAPWAP is the concept of a ___.
split media access control (MAC)
The CAPWAP split MAC concept does all of the functions normally performed by individual APs and distributes them between two functional components:
AP MAC Functions
WLC MAC Functions
Which function?
(AP MAC or WLC MAC)
Beacons and probe responses
AP MAC
Which function?
(AP MAC or WLC MAC)
Packet acknowledgements and retransmissions
AP MAC
Which function?
(AP MAC or WLC MAC)
Frame queueing and packet prioritization
AP MAC
Which function?
(AP MAC or WLC MAC)
MAC layer data encryption and decryption
AP MAC
Which function?
(AP MAC or WLC MAC)
Authentication
WLC MAC
Which function?
(AP MAC or WLC MAC)
Association and re-association of roaming clients
WLC MAC
Which function?
(AP MAC or WLC MAC)
Frame translation to other protocols
WLC MAC
Which function?
(AP MAC or WLC MAC)
Termination of 802.11 traffic on a wired interface
WLC MAC
___ is a protocol which provides security between the AP and the WLC. It allows them to communicate using encryption and prevents eavesdropping or tampering.
DTLS
TRUE OR FALSE
DTLS is enabled by default to secure the CAPWAP control channel but is disabled by default for the data channel
All CAPWAP management and control traffic exchanged between an AP and WLC is encrypted and secured by default to provide control plane privacy and prevent Man-In-the-Middle (MITM) attacks.
MITM attacks
Man-In-The-Middle
TRUE OR FALSE
Data encryption does not require a DTLS license to be installed on the WLC prior to being enabled on an AP
False
Data encryption requires a DTLS license to be installed on the WLC prior to being enabled on an AP
___ is a wireless solution for branch office and remote office deployments. It lets you configure and control access points in a branch office from the corporate office through a WAN link, without deploying a controller in each office.
FlexConnect
There are two modes of operation for the FlexConnect AP.
___: The WLC is reachable. In this mode the FlexConnect AP has CAPWAP connectivity with its WLC and can send traffic through the CAPWAP tunnel, as shown in the figure. The WLC performs all its CAPWAP functions.
Connected mode
There are two modes of operation for the FlexConnect AP.
__: The WLC is unreachable. The FlexConnect has lost or failed to establish CAPWAP connectivity with its WLC. In this mode, a FlexConnect AP can assume some of the WLC functions such as switching client data traffic locally and performing client authentication locally.
Standalone mode