07-23-2012 02:17 PM - edited 07-03-2021 10:26 PM
IS H-REAP thet best way to secure traffic from one your WLC to a remote AP? example, I have a place with a T1 connection and only 2 AP's...The traffic has to be encrypted, from the AP to the Controller, not just from the client to the controller.
hope this makes sense
Thanks
Solved! Go to Solution.
07-23-2012 02:26 PM
Data traffic is not encrypted unless you enable dtls. H-REAP/FlexConnect places traffic locally on your LAN so traffic would be the same as your wired.
Sent from Cisco Technical Support iPhone App
07-23-2012 02:33 PM
capwap control traffic is always encrypted while capwap data traffic is not, so you're fine there.
locally switched traffic are off capwap and doesn't hit WLC.
if you need centrally switched data traffic encrypted then you need data DTLS license(its free) with DTLS option enabled on those APs.
07-23-2012 02:26 PM
Data traffic is not encrypted unless you enable dtls. H-REAP/FlexConnect places traffic locally on your LAN so traffic would be the same as your wired.
Sent from Cisco Technical Support iPhone App
07-23-2012 02:33 PM
capwap control traffic is always encrypted while capwap data traffic is not, so you're fine there.
locally switched traffic are off capwap and doesn't hit WLC.
if you need centrally switched data traffic encrypted then you need data DTLS license(its free) with DTLS option enabled on those APs.
07-24-2012 05:54 AM
Thanks, HREAP will be doing central switching, so I need to turn on the dtls
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide