07-23-2012 02:17 PM - edited 07-03-2021 10:26 PM
IS H-REAP thet best way to secure traffic from one your WLC to a remote AP? example, I have a place with a T1 connection and only 2 AP's...The traffic has to be encrypted, from the AP to the Controller, not just from the client to the controller.
hope this makes sense
Thanks
Solved! Go to Solution.
07-23-2012 02:26 PM
Data traffic is not encrypted unless you enable dtls. H-REAP/FlexConnect places traffic locally on your LAN so traffic would be the same as your wired.
Sent from Cisco Technical Support iPhone App
07-23-2012 02:33 PM
capwap control traffic is always encrypted while capwap data traffic is not, so you're fine there.
locally switched traffic are off capwap and doesn't hit WLC.
if you need centrally switched data traffic encrypted then you need data DTLS license(its free) with DTLS option enabled on those APs.
07-23-2012 02:26 PM
Data traffic is not encrypted unless you enable dtls. H-REAP/FlexConnect places traffic locally on your LAN so traffic would be the same as your wired.
Sent from Cisco Technical Support iPhone App
07-23-2012 02:33 PM
capwap control traffic is always encrypted while capwap data traffic is not, so you're fine there.
locally switched traffic are off capwap and doesn't hit WLC.
if you need centrally switched data traffic encrypted then you need data DTLS license(its free) with DTLS option enabled on those APs.
07-24-2012 05:54 AM
Thanks, HREAP will be doing central switching, so I need to turn on the dtls
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: