11-23-2014 04:43 AM - edited 07-05-2021 02:00 AM
hi,
I need to know how can I confirm using command line or GUI of WLC WISM2 7.4 the CAPWAP tunnel is encrypted?!
I know that CAPWAP tunnel is usually encrypted not option, right ?!
11-23-2014 10:49 AM
No, it is a configurable option. By default all CAPWAP control packets are encrypted & not CAPWAP data packets. AP should support DTLS encryption & it may affect the performance of the AP. Refer below for detail
You can configure it using CLI like below
config ap link-encryption {enable | disable} {all | Cisco_AP}
You can verify it using below CLI
show ap link-encryption all
HTH
Rasika
**** Pls rate all useful responses ****
11-23-2014 01:26 PM
thanks Manannalage ras... for your reply,
but does it require a license?if yes how can I verify that i have it or not?
thanks
11-23-2014 02:49 PM
Hi Mohamed,
DTLS license should be enabled by default on your WLC (unless it has LDPE image).
See below for detail
http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn76mr03.html#pgfId-1162652
HTH
Rasika
**** Pls rate all useful responses ****
11-24-2014 07:21 AM
+5 Ras ..
Something else to add, when you use Office Extends, for example, AP600 the tunnel is automagically encrypted .. Its little things like this that drive me crazy!
11-24-2014 10:33 AM
Thank you George :)
11-24-2014 10:18 AM
Hi,
You can also use "sh dtls connection" to see all the dtls tunnels ( capwap data or capwap control ) between AP and controllers with their cipher suites in use.
Regards
Dhiresh
**Please rate helpful posts**
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide