<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Disable iCAP on AP's in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4667805#M245043</link>
    <description>&lt;P&gt;Dear all,&lt;BR /&gt;&lt;BR /&gt;Let me start with the Problem first.&lt;BR /&gt;Our customer is reporting a lot of Firewall drops on the Port 32626, from AP's to DNAC.&lt;BR /&gt;After some searching, reading documentation and so on, I found out this is the Intelligent Capture feature.&lt;BR /&gt;&lt;BR /&gt;What I found out is that in the AP Join Profile the iCAP is disabled. And therefore should be applied to every AP.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="icap.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/159748i64E4D1342678F185/image-size/medium?v=v2&amp;amp;px=400" role="button" title="icap.png" alt="icap.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorVida44_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;But if I go into each AP it will have a setting of "Not Configured" and not "Disabled".&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="icap2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/159749iDBF7488346986551/image-size/medium?v=v2&amp;amp;px=400" role="button" title="icap2.png" alt="icap2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I manually disable this in GUI, after a restart the setting will go back to "Not Configured".&lt;BR /&gt;But even with all of this set as "Disabled" I can still see the Access Points in the &lt;EM&gt;sh ap icap serviceability summary &lt;/EM&gt;as "connecting".&lt;BR /&gt;(Although this could be the status of connection from DNAC to WLC and not the other way around.)&lt;BR /&gt;Also, there is no option in CLI to set it as "disabled" which could probably mean that the "Not Configured" and "Disabled" are one and the same.&lt;BR /&gt;&lt;BR /&gt;Which now brings me to the question of how I can disable Intelligent Capture on the AP level since the above methods are not working?&lt;BR /&gt;The documentation doesn't show any command/button that disables Intelligent Capture on the AP's.&lt;BR /&gt;The goal is to not have any Traffic from AP in the direct direction to DNAC and with this also no Firewall drops.&lt;BR /&gt;&lt;BR /&gt;WLC Version 17.3.4c&lt;BR /&gt;WLC Model: 9800-CL&lt;BR /&gt;AP Model: 9120AX&lt;BR /&gt;&lt;BR /&gt;Any help would be appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2022 12:26:07 GMT</pubDate>
    <dc:creator>Vida44</dc:creator>
    <dc:date>2022-08-11T12:26:07Z</dc:date>
    <item>
      <title>Disable iCAP on AP's</title>
      <link>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4667805#M245043</link>
      <description>&lt;P&gt;Dear all,&lt;BR /&gt;&lt;BR /&gt;Let me start with the Problem first.&lt;BR /&gt;Our customer is reporting a lot of Firewall drops on the Port 32626, from AP's to DNAC.&lt;BR /&gt;After some searching, reading documentation and so on, I found out this is the Intelligent Capture feature.&lt;BR /&gt;&lt;BR /&gt;What I found out is that in the AP Join Profile the iCAP is disabled. And therefore should be applied to every AP.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="icap.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/159748i64E4D1342678F185/image-size/medium?v=v2&amp;amp;px=400" role="button" title="icap.png" alt="icap.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorVida44_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;But if I go into each AP it will have a setting of "Not Configured" and not "Disabled".&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="icap2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/159749iDBF7488346986551/image-size/medium?v=v2&amp;amp;px=400" role="button" title="icap2.png" alt="icap2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I manually disable this in GUI, after a restart the setting will go back to "Not Configured".&lt;BR /&gt;But even with all of this set as "Disabled" I can still see the Access Points in the &lt;EM&gt;sh ap icap serviceability summary &lt;/EM&gt;as "connecting".&lt;BR /&gt;(Although this could be the status of connection from DNAC to WLC and not the other way around.)&lt;BR /&gt;Also, there is no option in CLI to set it as "disabled" which could probably mean that the "Not Configured" and "Disabled" are one and the same.&lt;BR /&gt;&lt;BR /&gt;Which now brings me to the question of how I can disable Intelligent Capture on the AP level since the above methods are not working?&lt;BR /&gt;The documentation doesn't show any command/button that disables Intelligent Capture on the AP's.&lt;BR /&gt;The goal is to not have any Traffic from AP in the direct direction to DNAC and with this also no Firewall drops.&lt;BR /&gt;&lt;BR /&gt;WLC Version 17.3.4c&lt;BR /&gt;WLC Model: 9800-CL&lt;BR /&gt;AP Model: 9120AX&lt;BR /&gt;&lt;BR /&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 12:26:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4667805#M245043</guid>
      <dc:creator>Vida44</dc:creator>
      <dc:date>2022-08-11T12:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Disable iCAP on AP's</title>
      <link>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4667808#M245044</link>
      <description>&lt;P&gt;You should rather open the firewall to allow this traffic, as this can be quite useful for troubleshooting clients in DNAC. I think this gets used as soon as you do a Live Trace of a client and disabled again if you click stop.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in my opinion this is an essential feature of DNAC and should/can not be disabled.&lt;/P&gt;
&lt;P&gt;More information about the ports that should be open:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/1-3/install_guide/M5/b_cisco_dna_center_install_guide_1_3_M5/b_cisco_dna_center_install_guide_1_3_M5_chapter_01.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/1-3/install_guide/M5/b_cisco_dna_center_install_guide_1_3_M5/b_cisco_dna_center_install_guide_1_3_M5_chapter_01.html&lt;/A&gt;&amp;nbsp;and here Table 7.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 12:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4667808#M245044</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-08-11T12:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disable iCAP on AP's</title>
      <link>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4669184#M245087</link>
      <description>&lt;P&gt;We are looking into opening the port for this traffic, but there are some compliance issues which make this problematic.&lt;BR /&gt;Hence the question on how to disable this.&lt;/P&gt;
&lt;P&gt;Of course, ignoring the Firewall blocks is possible (the customer will need to live with it), but I need to explore all options before going into that direction.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323352"&gt;@patoberli&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;But in my opinion this is an essential feature of DNAC and should/can not be disabled.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Since the DNAC cannot receive this traffic due to Firewall block, then its function in DNAC is not relevant. Decision to disable/enable a feature should be left to the Customer and not Cisco. Just my two Cents. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;And please do not misunderstand me, I would love to have this in DNAC for troubleshooting purposes.&lt;BR /&gt;&lt;BR /&gt;In any case if it is not possible to disable it (at this moment) I can go with this information to the customer.&lt;BR /&gt;My question was more in the direction if I missed something in some Documentation.&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 12:32:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4669184#M245087</guid>
      <dc:creator>Vida44</dc:creator>
      <dc:date>2022-08-15T12:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Disable iCAP on AP's</title>
      <link>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4967872#M263595</link>
      <description>&lt;P&gt;... btw link is not working ...&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 01:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4967872#M263595</guid>
      <dc:creator>stayd</dc:creator>
      <dc:date>2023-11-29T01:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: Disable iCAP on AP's</title>
      <link>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4967875#M263596</link>
      <description>&lt;P&gt;Intelligent Capture is not just for packet capture data but also AP and client statistics, and spectrum data, it even allows&amp;nbsp; you to access data from APs that is not available from wireless controllers.&lt;/P&gt;
&lt;P&gt;If you haven't already, then look at "Enable and Manage Intelligent Capture for an Access Point" section in this &lt;A href="https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center-assurance/2-2-3/b_cisco_dna_assurance_2_2_3_ug/b_cisco_dna_assurance_2_2_3_ug_chapter_01110.html" target="_self"&gt;document&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 01:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-icap-on-ap-s/m-p/4967875#M263596</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-11-29T01:39:52Z</dc:date>
    </item>
  </channel>
</rss>

