1. If I have 10 Flexconnect APs at my branch, would that create 10 CAPWAP tunnels to the WLC located in HQ.
> You might be getting confuesd with mobility tunnels. The AP can support the max it is licensed for
2. How often the flexconnect AP will send the CAPWAP to WLC?
>
- AP Heartbeat Timeout—AP Heartbeat timeout value that you can enter. The valid range is 10 to 30 for the Cisco 7500 Series Controller and 1 to 30 for other platforms.
- Local Mode AP Fast Heartbeat Timer State—Fast heartbeat timer that you can enable or disable for access points in local mode. The default is disable.
3. What is the size of flexconnect CAPWAP tunnel keepalives?
> Look at the previous question
4. By default, is CAPWAP tunnel (regardless local or flexconnec) encrypted?
> Only if you enable Data Encryption, by default this is not enabled. Typically use only on OfficeExtend
5. The DMZ firewall, what ports should be allowed for the guest traffic (anchor WLC)? Is it just 5246 or 5246 and 5247?
>This doesn't matter since guest traffic would be central switching and you would have a mobility anchor to the guest anchor WLC
6. Is EoIP encrypted or clear text?
> Data is not encrypted unless you enable Data Encryption with the DTLS license.
Some links:
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_white_paper09186a0080901caa.shtml
http://www.cisco.com/en/US/products/ps11635/products_tech_note09186a0080b7f141.shtml#ft
Thanks,
Scott
Help out other by using the rating system and marking answered questions as "Answered"
-Scott
*** Please rate helpful posts ***