Network Assurance Flashcards
(45 cards)
CAPWAP ports
5246-5247
CAPWAP - Control Channel Traffic Port
5246
CAPWAP - Data Channel Traffic Port
5247
TFTP Port
69
What Port can AP’s use to transfer data files
TFTP - Port 69
What port is used by mobility communications
16666-16667
Mobility Communications Port - 16666
Encrypted
Mobility COmmunications Port - 16667
Not encrypted
NETCONF SSH Subsystem Port
830
What type of credentials are configured on Access Points to ensure those credentials are avalaible everywhere?
Global Credentials
Can you override global credentials for a specific Cisco IOS AP?
Yes
Cisco AP DHCP Option
43
Cisco AP DNS option
cisco-capwap-controller
What broadcast address does a Cisco AP use to find a WLC?
255.255.255.255
How does (order) an AP learn about WLC@s
- DHCP option 43 (good for global companies where offices and controllers are on different continents).
- DNS entry for cisco-capwap-controller (good for local businesses - can also be used to find where brand new APs join) If you use CAPWAP, make sure there is a DNS entry for cisco-capwap-controller.
- Management IP addresses of controllers the LAP remembers previously.
- A Layer 3 broadcast on the subnet.
- Statically configured information.
- Controllers present in the mobility group of the WLC the AP last joined.
“DHCP option 43 is used by large companies to localize the information by the DHCP. This method is used by large enterprises that have a single DNS suffix. For example….” give an example
Cisco owns buildings in Europe, Australia, and the United States. In order to ensure that the LAPs only join controllers locally, Cisco cannot use a DNS entry and must use DHCP option 43 information to tell the LAPs what the management IP address of their local controller is.
Who created CAPWAP
IETF
CAPWAP is based
Lightweight Access Point Protocol (LWAPP) but adds additional security with Datagram Transport Layer Security (DTLS)
CAPWAP IPv4 Protocol Number
17 - uses UDP ports 5246 (control) and 5247 (data)
In an AP Split MAC architecture the following are examples of use cases performed by what?
802.11 authentication
802.11 association and re-association (mobility)
802.11 frame translation and bridging
802.1X/EAP/RADIUS processing
Termination of 802.11 traffic on a wired interface, except in the case of FlexConnect APs (discussed later in this guide)
The AP itself
What certificate does AP’s use for certificates when forming initial DTLS tunnels?
Manufacturing Installed Certificate (MIC)
Installed by cisco when shipped
What type of security archtiecture facilitates this VPN?
FlexConnect
What message types facilitate an inter-subnet WLC controller roam?
Mobiliy
In a Cisco WLC with full Mobility setup - does a inter-subnet controller roam result in a client IP address change?
No - WLC setup an “ANchor” original and “Foreign” entry in both WLC CLient Databases
User keeps original IP and “Foreign” client database tunnels traffic to anchor database