<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobility group - high cipher option. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4079926#M108609</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324872"&gt;@Rasika Nayanajith&lt;/a&gt;&amp;nbsp;Thank you for the reply! I appreciate it a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll try to be more specific.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you have already mentioned here&amp;nbsp;&lt;A href="https://community.cisco.com/t5/other-wireless-mobility-subjects/mobility-control-amp-data-encryption/m-p/3955950/highlight/true#M101919" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/other-wireless-mobility-subjects/mobility-control-amp-data-encryption/m-p/3955950/highlight/true#M101919&lt;/A&gt;&amp;nbsp;, encrypted mobility messaging via CAPWAP DTLS is enabled by 2 commands:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config mobility group member add&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;EM&gt;peer-mac-addr&amp;nbsp;peer-ip-addr&amp;nbsp;group-name&amp;nbsp;&lt;/EM&gt;&lt;STRONG&gt;&lt;SPAN class="keyword kwd"&gt;encrypt&amp;nbsp;&lt;/SPAN&gt;{&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;enable&lt;/SPAN&gt;&amp;nbsp;|&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;disable&lt;/SPAN&gt;} &lt;/STRONG&gt;&lt;EM&gt;(which is Secure Mobility - Enabled in GUI)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config mobility group member data-dtls&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;EM&gt;peer-mac-addr&amp;nbsp;&lt;/EM&gt;&lt;STRONG&gt;{&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;enable&lt;/SPAN&gt;&amp;nbsp;|&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;disable&lt;/SPAN&gt;}&amp;nbsp;&lt;/STRONG&gt;&lt;EM&gt;(which is Data Tunnel Encryption - Enabled in GUI)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The same is described in the configuration guide for 8-10 you provided earlier &lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/encrypted_mobility_tunnel.html" target="_self" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/encrypted_mobility_tunnel.html&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe these 2 commands will make the WLCs to use CAPWAP DTLS instead of EoIP for Mobility Data traffic indeed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am asking about is "High Cipher" selection. Please look at the screenshot. I've highlighted additional 3rd option we can use with the previous 2 commands. But I can't find it's description anywhere and this is what I'm asking about.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="333.png" style="width: 776px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/73758i82660DA7866EBE51/image-size/large?v=v2&amp;amp;px=999" role="button" title="333.png" alt="333.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 May 2020 17:55:45 GMT</pubDate>
    <dc:creator>Murinos</dc:creator>
    <dc:date>2020-05-05T17:55:45Z</dc:date>
    <item>
      <title>Mobility group - high cipher option.</title>
      <link>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4079113#M108607</link>
      <description>&lt;P&gt;Good day!&lt;/P&gt;&lt;P&gt;I wonder, what does&amp;nbsp;"High Cipher" option do in Mobility Group member setup? This is 8.10.105 release.&lt;/P&gt;&lt;P&gt;Please, look at the screenshot attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could not find any mention of it neither in the configuration guide for release 8.10 nor anywhere else...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 19:01:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4079113#M108607</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2021-07-05T19:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility group - high cipher option.</title>
      <link>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4079257#M108608</link>
      <description>&lt;P&gt;This will enable encrypted mobility messaging (CAPWAP DTLS based) instead of unencrypted EoIP&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/encrypted_mobility_tunnel.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/encrypted_mobility_tunnel.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 21:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4079257#M108608</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2020-05-04T21:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility group - high cipher option.</title>
      <link>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4079926#M108609</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324872"&gt;@Rasika Nayanajith&lt;/a&gt;&amp;nbsp;Thank you for the reply! I appreciate it a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll try to be more specific.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you have already mentioned here&amp;nbsp;&lt;A href="https://community.cisco.com/t5/other-wireless-mobility-subjects/mobility-control-amp-data-encryption/m-p/3955950/highlight/true#M101919" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/other-wireless-mobility-subjects/mobility-control-amp-data-encryption/m-p/3955950/highlight/true#M101919&lt;/A&gt;&amp;nbsp;, encrypted mobility messaging via CAPWAP DTLS is enabled by 2 commands:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config mobility group member add&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;EM&gt;peer-mac-addr&amp;nbsp;peer-ip-addr&amp;nbsp;group-name&amp;nbsp;&lt;/EM&gt;&lt;STRONG&gt;&lt;SPAN class="keyword kwd"&gt;encrypt&amp;nbsp;&lt;/SPAN&gt;{&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;enable&lt;/SPAN&gt;&amp;nbsp;|&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;disable&lt;/SPAN&gt;} &lt;/STRONG&gt;&lt;EM&gt;(which is Secure Mobility - Enabled in GUI)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;config mobility group member data-dtls&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;EM&gt;peer-mac-addr&amp;nbsp;&lt;/EM&gt;&lt;STRONG&gt;{&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;enable&lt;/SPAN&gt;&amp;nbsp;|&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;disable&lt;/SPAN&gt;}&amp;nbsp;&lt;/STRONG&gt;&lt;EM&gt;(which is Data Tunnel Encryption - Enabled in GUI)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The same is described in the configuration guide for 8-10 you provided earlier &lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/encrypted_mobility_tunnel.html" target="_self" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/encrypted_mobility_tunnel.html&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe these 2 commands will make the WLCs to use CAPWAP DTLS instead of EoIP for Mobility Data traffic indeed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am asking about is "High Cipher" selection. Please look at the screenshot. I've highlighted additional 3rd option we can use with the previous 2 commands. But I can't find it's description anywhere and this is what I'm asking about.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="333.png" style="width: 776px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/73758i82660DA7866EBE51/image-size/large?v=v2&amp;amp;px=999" role="button" title="333.png" alt="333.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 17:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4079926#M108609</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-05-05T17:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility group - high cipher option.</title>
      <link>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4080136#M108610</link>
      <description>&lt;P&gt;Thank you for reminding me of that old thread.&lt;/P&gt;
&lt;P&gt;You are right about documentation about that "high cipher option", I cannot find anything on cisco.com about it either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is what I think, it is for cipher suites support for a key length longer than 128 bits.&lt;/P&gt;
&lt;P&gt;Again, Cisco should provide more context around what exactly that feature means to avoid confusion. If I get anything else, I will keep you posted here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 01:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4080136#M108610</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2020-05-06T01:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility group - high cipher option.</title>
      <link>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4096050#M108611</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324872"&gt;@Rasika Nayanajith&lt;/a&gt;&amp;nbsp;You were right, I've asked TAC about it and they confirmed your version. They created a bug to fix this docomentation, so waiting for announce in next version of Deployment Guide.&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu45944" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu45944&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 10:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4096050#M108611</guid>
      <dc:creator>Murinos</dc:creator>
      <dc:date>2020-06-02T10:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility group - high cipher option.</title>
      <link>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4096449#M108612</link>
      <description>&lt;P&gt;Thank you for the bug to fix that documentation &amp;amp; give more clear information about those DTLS high ciphers options&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rasika&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 18:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-group-high-cipher-option/m-p/4096449#M108612</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2023-05-30T18:50:44Z</dc:date>
    </item>
  </channel>
</rss>

