03-15-2020 11:06 PM - edited 07-05-2021 11:51 AM
Hi All
I have some question about the CAPWAP process.
So in our company the access points need the dns entry to find the wireless controller.
So the AP receive the IP of the active WLC. Then the AP will connect. But is there something like a handshake between the AP and the WLC?
Cheers
Andi
Solved! Go to Solution.
03-16-2020 04:39 PM
Hi Andi,
Yes, once AP discover a WLC to join, it will go through the Join process. Prior to send Join Request, AP has to establish DTLS tunnel with WLC. Here is that flow of those packet in DTLS handshake. Refer this post for detail
https://mrncciew.com/2013/03/17/ap-registration/
HTH
Rasika
*** Pls rate all useful responses ***
03-15-2020 11:14 PM
03-16-2020 06:04 AM
Hi,
Regardless of how you setup the AP to learn about the WLC, in the end they build a DTLS control-plane tunnel (CAPWAP), based on certificates, so the session is secure. As long as NTP is working correctly and certificates are valid, the AP is allowed to join the WLC; if required, you can configure in the WLC some kind of authorization, to control which LAP's can actually join the WLC, so that there is no way that someone plugs in a rogue LAP, knows about the WLC address, and it's instantly allowed to join.
Regards,
Cristian Matei.
03-16-2020 04:39 PM
Hi Andi,
Yes, once AP discover a WLC to join, it will go through the Join process. Prior to send Join Request, AP has to establish DTLS tunnel with WLC. Here is that flow of those packet in DTLS handshake. Refer this post for detail
https://mrncciew.com/2013/03/17/ap-registration/
HTH
Rasika
*** Pls rate all useful responses ***
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide