<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Enabling Data Link Encryption for Mobility Tunnels and APs? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5331890#M286466</link>
    <description>&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;SCENARIO:&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp; A mix of physical and virtual Cisco 9800 wireless controllers in a wireless mobility anchoring configuration for guest tunneling of different SSIDs.&amp;nbsp; The controllers are running 17.15.3 version of IOS XE.&amp;nbsp; Approximately 150-200 APs in the wireless environment.&amp;nbsp; Some SSIDs are doing FlexConnect in the policy at their local location.&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;GOAL:&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp; Looking at "secure mobility tunneling" and also enabling Data Link encryption for Access Points.&amp;nbsp; This is the guide I was perusing so far for reference:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/mobility.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/mobility.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;QUESTIONS:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;1) Is DTLS encryption enabled by default for mobility peer tunnels?&lt;BR /&gt;2) For APs: I see EAP-FAST / CAPWAP DTLS + options in dropdowns for "AP Join Profile &amp;gt; AP &amp;gt; General &amp;gt; EAP Auth Configuration" for in a custom AP join profile - is that a different feature/function, and/or is DTLS enabled for CAPWAP tunnels on APs by default?&lt;/P&gt;&lt;P&gt;3) What are the benefits of enabling Data Link encryption for the mobility peer tunnel, and for APs?&lt;BR /&gt;4) Does it cause an impact/disruption when the option is enabled/checking the box and applying?&lt;BR /&gt;5) Are there any client / performance considerations/impact for data link encrypted mobility tunnels for guest traffic anchoring, and for data link encrypted APs for clients in general (not just guest traffic WLANS)?&lt;BR /&gt;6) What is the DTLS High Cipher Only toggle for Mobility in the GUI?&lt;BR /&gt;7) For mobility peers that are showing Data Link Encryption Disabled, do they require re-adding as peers (rebuilding the tunnel?) in order to edit or add Data Link Encryption for mobility peers/between anchors and foreign controllers?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;AP Join Profile Options:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coolbreeze_1-1758314196323.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252223i5EEB6B6A93C2BE8A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coolbreeze_1-1758314196323.png" alt="coolbreeze_1-1758314196323.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coolbreeze_0-1758314858234.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252226iD3F23A421E103242/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coolbreeze_0-1758314858234.png" alt="coolbreeze_0-1758314858234.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Mobility Configuration Toggle, &amp;amp; Mobility Peer Status:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coolbreeze_2-1758314321025.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252224i518E18D395712427/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coolbreeze_2-1758314321025.png" alt="coolbreeze_2-1758314321025.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coolbreeze_3-1758314462975.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252225iD7F7A0F4AF44BB59/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coolbreeze_3-1758314462975.png" alt="coolbreeze_3-1758314462975.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Sep 2025 20:50:07 GMT</pubDate>
    <dc:creator>coolbreeze</dc:creator>
    <dc:date>2025-09-19T20:50:07Z</dc:date>
    <item>
      <title>Enabling Data Link Encryption for Mobility Tunnels and APs?</title>
      <link>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5331890#M286466</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;SCENARIO:&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp; A mix of physical and virtual Cisco 9800 wireless controllers in a wireless mobility anchoring configuration for guest tunneling of different SSIDs.&amp;nbsp; The controllers are running 17.15.3 version of IOS XE.&amp;nbsp; Approximately 150-200 APs in the wireless environment.&amp;nbsp; Some SSIDs are doing FlexConnect in the policy at their local location.&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;GOAL:&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp; Looking at "secure mobility tunneling" and also enabling Data Link encryption for Access Points.&amp;nbsp; This is the guide I was perusing so far for reference:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/mobility.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/mobility.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;QUESTIONS:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;1) Is DTLS encryption enabled by default for mobility peer tunnels?&lt;BR /&gt;2) For APs: I see EAP-FAST / CAPWAP DTLS + options in dropdowns for "AP Join Profile &amp;gt; AP &amp;gt; General &amp;gt; EAP Auth Configuration" for in a custom AP join profile - is that a different feature/function, and/or is DTLS enabled for CAPWAP tunnels on APs by default?&lt;/P&gt;&lt;P&gt;3) What are the benefits of enabling Data Link encryption for the mobility peer tunnel, and for APs?&lt;BR /&gt;4) Does it cause an impact/disruption when the option is enabled/checking the box and applying?&lt;BR /&gt;5) Are there any client / performance considerations/impact for data link encrypted mobility tunnels for guest traffic anchoring, and for data link encrypted APs for clients in general (not just guest traffic WLANS)?&lt;BR /&gt;6) What is the DTLS High Cipher Only toggle for Mobility in the GUI?&lt;BR /&gt;7) For mobility peers that are showing Data Link Encryption Disabled, do they require re-adding as peers (rebuilding the tunnel?) in order to edit or add Data Link Encryption for mobility peers/between anchors and foreign controllers?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;AP Join Profile Options:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coolbreeze_1-1758314196323.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252223i5EEB6B6A93C2BE8A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coolbreeze_1-1758314196323.png" alt="coolbreeze_1-1758314196323.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coolbreeze_0-1758314858234.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252226iD3F23A421E103242/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coolbreeze_0-1758314858234.png" alt="coolbreeze_0-1758314858234.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Mobility Configuration Toggle, &amp;amp; Mobility Peer Status:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coolbreeze_2-1758314321025.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252224i518E18D395712427/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coolbreeze_2-1758314321025.png" alt="coolbreeze_2-1758314321025.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coolbreeze_3-1758314462975.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252225iD7F7A0F4AF44BB59/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coolbreeze_3-1758314462975.png" alt="coolbreeze_3-1758314462975.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2025 20:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5331890#M286466</guid>
      <dc:creator>coolbreeze</dc:creator>
      <dc:date>2025-09-19T20:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Data Link Encryption for Mobility Tunnels and APs?</title>
      <link>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5331979#M286467</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/444082"&gt;@coolbreeze&lt;/a&gt;&amp;nbsp; &amp;nbsp; 1)&amp;nbsp; A&amp;nbsp;&lt;SPAN&gt;9800 based mobility tunnel is always secure and encrypted.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3)&amp;nbsp;Confidentiality of mobility control/data traffic ; Align with regulatory requirements &lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(e.g., GDPR, ISO 27001) for encrypted inter-controller communication.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5)&amp;nbsp;If anchor controller is overloaded due to DTLS processing, clients may see slower DHCP, captive portal redirects, or guest traffic latency.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6)&amp;nbsp;You&amp;nbsp;&lt;FONT color="#000000"&gt;must enable&lt;STRONG&gt;&amp;nbsp;&lt;SPAN class="ph uicontrol"&gt;High Cipher&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;only if you require DTLS &lt;STRONG&gt;v1.2 encryption.&lt;/STRONG&gt;&amp;nbsp;The default value is&amp;nbsp;&lt;SPAN class="ph uicontrol"&gt;Disabled&lt;/SPAN&gt;.&amp;nbsp;In disabled state, DTLS v1.0 encryption is enabled&lt;BR /&gt;&lt;/FONT&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;If used the controllers advertise&lt;FONT color="#008000"&gt;&lt;EM&gt; higher cipher suites&lt;/EM&gt; &lt;/FONT&gt;during DTLS handshakes.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Verify the setting with :&amp;nbsp;&lt;EM&gt; &amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;show wireless mobility summary&amp;nbsp; | inc Cipher&lt;BR /&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7)&amp;nbsp;&amp;nbsp;You do &lt;EM&gt;not&lt;/EM&gt; need to delete and re-add the mobility peer to enable DTLS encryption. &lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; But&amp;nbsp;The controllers will negotiate the DTLS handshake with the peer which may cause a short&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; latency effect on the mobility tunnels&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Sep 2025 10:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5331979#M286467</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-09-20T10:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Data Link Encryption for Mobility Tunnels and APs?</title>
      <link>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5332449#M286484</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;! I realized I mistyped a bit, can you help demystify what is the difference for enabling "Data Encryption" and "Data Link Encryption"?&amp;nbsp; I noticed my mobility peer screenshot shows Data Link Encryption Disabled so am confused on that (unless it would pertain only to v1.2 encryption being enabled as you mentioned in #6).&lt;/P&gt;&lt;P&gt;Is encryption for data (higher layer/payload information) included, or is it just CAPWAP control packets on APs and mobility tunnel inter-controller packets?&lt;/P&gt;&lt;P&gt;Still wondering what that checkbox "Enable Data Encryption" will do for AP join profile, and the impact, assuming it is something different than DTLS.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 15:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5332449#M286484</guid>
      <dc:creator>coolbreeze</dc:creator>
      <dc:date>2025-09-22T15:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Data Link Encryption for Mobility Tunnels and APs?</title>
      <link>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5332461#M286486</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/444082"&gt;@coolbreeze&lt;/a&gt;&amp;nbsp; &lt;STRONG&gt;&amp;nbsp;Enable Data Encryption&lt;/STRONG&gt; enables&amp;nbsp;&lt;SPAN&gt;Datagram Transport Layer Security (DTLS) &lt;FONT color="#008000"&gt;&lt;EM&gt;&lt;STRONG&gt;data&lt;/STRONG&gt; encryption&lt;BR /&gt;&lt;/EM&gt;&lt;FONT color="#000000"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;So that applies to&amp;nbsp; simple/single&amp;nbsp; DTLS connections only&lt;/FONT&gt;&lt;EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;FONT color="#000000"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp;Data link encryption&lt;/STRONG&gt; (encrypting client data traffic between controllers) &lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;is optional and is recommended if a&amp;nbsp;&lt;U&gt;&lt;EM&gt;mobility tunnel&lt;/EM&gt;&lt;/U&gt; is built on top of a nontrusted network.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It is disabled by default, and if enabled, it has to be done on both sides.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#008000"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp; &amp;nbsp;M.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 16:29:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/enabling-data-link-encryption-for-mobility-tunnels-and-aps/m-p/5332461#M286486</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-09-22T16:29:36Z</dc:date>
    </item>
  </channel>
</rss>

