Soru

Zorluk: ZorWireless Principles and Architecture

An enterprise network administrator is deploying a centralized Cisco Wireless LAN Controller (WLC) architecture utilizing CAPWAP tunnels for Lightweight Access Point (LAP) management and traffic transport. Which two statements correctly describe the transport layer protocols and security characteristics used by CAPWAP? (Choose two.)

  1. CAPWAP Control traffic uses UDP port 5246 and is encrypted by default using Datagram Transport Layer Security (DTLS).Cevap
  2. CAPWAP Data traffic uses UDP port 5247 and is unencrypted by default, though optional DTLS payload encryption can be enabled.Cevap
  3. C
    CAPWAP Control traffic uses TCP port 5246 to guarantee connection-oriented reliable delivery of management frames without encryption.
  4. D
    CAPWAP Data traffic uses TCP port 5247 to prevent packet loss for real-time wireless voice and video application traffic.
  5. E
    CAPWAP Control and Data tunnels are multiplexed over a single IPsec VPN tunnel established on UDP port 500.

Cevap

The correct statements are that CAPWAP Control traffic operates over UDP port 5246 with mandatory DTLS encryption, while CAPWAP Data traffic operates over UDP port 5247 and is unencrypted by default (with optional DTLS encryption support).
CAPWAP (Control and Provisioning of Wireless Access Points) protocol specifies UDP port 5246 for Control messages, which are encrypted using DTLS by default to secure WLC-to-AP management traffic. CAPWAP Data frames are transported over UDP port 5247, which defaults to unencrypted operational state to maximize throughput, while allowing optional DTLS payload encryption.

Adım Adım Çözüm

1
Analyze CAPWAP transport protocol selection.
CAPWAP uses UDP (User Datagram Protocol) rather than TCP for both Control and Data channels to eliminate head-of-line blocking and TCP sliding-window overhead over wireless medium links.
Lightweight access points and controllers handle reliability through CAPWAP retransmission timers and DTLS instead of TCP transport features.
2
Identify CAPWAP port assignments for Control and Data planes.
Control traffic communicates over UDP port 5246, while Data traffic communicates over UDP port 5247.
Separating Control and Data onto distinct UDP destination ports allows routers and firewalls to apply targeted QoS and security policies.
3
Evaluate encryption requirements for CAPWAP channels.
CAPWAP Control traffic requires DTLS encryption by default to safeguard configuration and management exchanges. CAPWAP Data traffic travels unencrypted by default to preserve throughput, though DTLS can be enabled if desired.
Default unencrypted data tunneling avoids severe performance penalties on hardware while protecting controller management transactions.

Anahtar Kavram

CAPWAP Protocol Architecture and UDP Port Operations
Bu soruyu puanla