A real-life situation
A school has 60 access points. Each one was set up by hand. Now the guest password must change, and someone has to log in to 60 APs, one by one. Halfway through, half the APs have the new password and half the old one. Teachers roaming between classrooms keep losing Wi-Fi.
The fix is to manage all APs from one place. That is what this lesson is about: the three ways enterprise APs are built and managed, how lightweight APs talk to a controller, and the AP modes the CCNA expects you to know.
What the three architectures are
| Architecture | Who controls the AP | Where client traffic goes | Good for |
|---|---|---|---|
| Autonomous | Each AP on its own (its own CLI or GUI) | Bridged straight onto the AP's switch port, one VLAN per SSID | A few APs, a home or small office |
| Lightweight + WLC | A Wireless LAN Controller (WLC), through CAPWAP | Tunnelled to the WLC in CAPWAP (local mode), or switched locally (FlexConnect) | Campuses with many APs |
| Cloud-managed (e.g. Cisco Meraki) | A dashboard in the cloud | Bridged locally at the AP; only management goes to the cloud | Many small sites, little IT staff |
An autonomous AP is a complete device: it runs its own configuration, security and RF settings. An AP with two SSIDs mapped to two VLANs needs an 802.1Q trunk to its switch. Roaming between autonomous APs is slower because each one works alone.
A lightweight AP (LAP) can't work on its own. It downloads its configuration and software from a WLC and does only the time-critical work itself.
A cloud-managed AP is configured from a web dashboard. If the internet link fails, the AP keeps serving clients with its last settings, but you can't change anything until the link returns.
Why split-MAC: who does what
The 802.11 standard defines a lot of work at the MAC layer. Some of it must happen within microseconds, right at the radio. Some of it is about policy and the big picture. Cisco splits the two. This is called split-MAC:
| Lightweight AP (real-time) | WLC (management) |
|---|---|
| Sending beacons and answering probes | Client authentication (with RADIUS) and association |
| Sending ACKs and retransmitting frames | Security policy, QoS policy, WLAN to VLAN mapping |
| Queueing and prioritising frames | Roaming between APs |
| Encrypting and decrypting on the air | RF management (channels and power, RRM) |
| MAC-layer handling of the radio | AP software images and configuration |
Because the WLC sees every AP and every client, it can choose channels for all APs together, keep a client's session when it roams, and push one change to all APs at once.
How CAPWAP carries the traffic
The AP and WLC talk with CAPWAP (Control And Provisioning of Wireless Access Points, RFC 5415). It is an open standard based on Cisco's older LWAPP. CAPWAP builds two tunnels between the AP's IP address and the WLC's management IP address:
- Control tunnel, UDP 5246: AP configuration, software, radio settings. Always encrypted with DTLS (TLS over UDP).
- Data tunnel, UDP 5247: client frames. Not encrypted by default.
Because CAPWAP runs over IP, the AP and WLC can be in different subnets, even different buildings. In the lab, AP1 is in VLAN 30 (10.10.30.21) and WLC1 is in VLAN 99 (10.10.99.10); SW1 routes between them.
- 1. The laptop sends a frame to AP1. It is encrypted on the air with WPA2 or WPA3. AP1 decrypts it.
- 2. AP1 tunnels it to WLC1. AP1 wraps the frame in CAPWAP, UDP 5247 and an IP header from 10.10.30.21 to 10.10.99.10. SW1 just routes a UDP packet.
- 3. WLC1 puts it on the client VLAN. WLC1 removes the tunnel and sends the frame out its trunk tagged VLAN 10, the VLAN mapped to the Staff WLAN. SW1 (10.10.10.1) routes it on.
- 4. Control traffic uses the other tunnel. Configuration and radio settings flow on UDP 5246, protected by DTLS.
AP1 (10.10.30.21) → SW1 → WLC1 (10.10.99.10). The switches route and switch an ordinary UDP packet; only the WLC opens it.
How an AP finds and joins a WLC
A new lightweight AP boots with no idea where its controller is. It first gets an IP address (usually by DHCP), then looks for WLCs in this order of methods:
- Broadcast a discovery request on its local subnet (works only if a WLC is in the same subnet).
- WLC addresses it learned before (stored in the AP's memory), and addresses of other WLCs in the same mobility group.
- DHCP option 43: the DHCP server hands out the WLC's IP address.
- DNS: the AP looks up
CISCO-CAPWAP-CONTROLLER.<domain>using the domain name it got from DHCP. - Primary, secondary and tertiary WLCs configured on the AP itself (once it has joined before).
From all the answers, the AP picks a WLC: first a configured primary controller, otherwise the least-loaded one. Then the join begins:
1. DHCP (with option 43) · AP ↔ DHCP · UDP 68 ↔ 67
AP1 gets 10.10.30.21, gateway 10.10.30.1, and option 43 pointing to 10.10.99.10.
- Mode:
- Local
- Controller:
- WLC1 10.10.99.10
- Tunnels:
- Control 5246 (DTLS), data 5247
WLC deployment options
The controller itself can live in different places:
| Deployment | Where the WLC runs | Typical size |
|---|---|---|
| Unified (centralized) | A hardware appliance in the data centre or core | Large campus, up to thousands of APs |
| Cloud-based | A virtual WLC (e.g. Catalyst 9800-CL) in a private or public cloud | Medium to large |
| Embedded | Software inside an access-layer switch | Branch, small campus |
| Inside an AP | One AP also acts as the controller (Mobility Express, or Embedded Wireless Controller on Catalyst 9100 APs) | Small sites, around 100 APs or fewer |
AP modes
A lightweight AP can be put in one of several modes from the WLC. The CCNA lists these:
| Mode | What the AP does |
|---|---|
| Local | The default. Serves clients and tunnels all their traffic to the WLC. Briefly scans other channels for rogues and RRM data. |
| FlexConnect | Serves clients and can switch their traffic locally onto the branch switch, so it doesn't cross the WAN. Keeps working if the WAN link to the WLC goes down. |
| Monitor | Doesn't serve clients. Listens on all channels for rogue APs, attacks (IDS) and location tracking. |
| Sniffer | Captures 802.11 frames on one channel and sends them to a PC running a packet analyser like Wireshark. |
| Rogue detector | Radio off. Watches the wired network (ARP) to find rogue APs plugged into your switches. |
| SE-Connect | Spectrum Expert: a spectrum analyser that finds non-Wi-Fi interference (microwaves, cameras). |
| Bridge / Mesh | Builds wireless links to other APs, point-to-point or mesh, to reach places with no cable. |
| Flex+Bridge | FlexConnect and mesh together on one AP. |
How to configure the switch ports on Cisco IOS
The AP itself is configured from the WLC, but the switch port it plugs into is yours. The right port type depends on the mode:
interface GigabitEthernet1/0/10
description AP1 (lightweight, local mode)
switchport mode access
switchport access vlan 30
spanning-tree portfast
power inline autoLocal mode: an access port in the AP VLAN. Client VLANs are not needed here because client traffic is inside CAPWAP. PortFast lets the AP get an address quickly; PoE powers it.
interface GigabitEthernet1/0/11
description AP2 (FlexConnect, local switching)
switchport mode trunk
switchport trunk native vlan 30
switchport trunk allowed vlan 10,20,30
spanning-tree portfast trunkFlexConnect with local switching (or an autonomous AP with several SSIDs): a trunk. The AP's own address is in the native VLAN 30; client traffic is tagged 10 and 20.
On the DHCP server for the AP VLAN, option 43 tells APs where WLC1 is. On a Cisco IOS DHCP server, the value is a hex string: type f1, length (4 bytes per WLC), then the WLC address in hex. 10.10.99.10 is 0a0a630a:
ip dhcp pool AP-VLAN30
network 10.10.30.0 255.255.255.0
default-router 10.10.30.1
option 43 hex f1040a0a630af1 = type, 04 = one WLC (4 bytes), 0a0a630a = 10.10.99.10. For two WLCs the length is 08 and both addresses follow.
How to verify it
On SW1, CDP shows the AP on its port. On a Catalyst 9800 WLC (IOS XE), show ap summary lists every joined AP:
SW1#show cdp neighbors GigabitEthernet1/0/10 Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone Device ID Local Intrfce Holdtme Capability Platform Port ID AP1 Gig 1/0/10 142 T I C9120AXI- Gig 0
WLC1#show ap summary Number of APs: 2 AP Name Slots AP Model Ethernet MAC Radio MAC Location Country IP Address State ------------------------------------------------------------------------------------------------------- AP1 2 C9120AXI-B a4b2.3c11.2201 a4b2.3c44.5500 Floor 1 US 10.10.30.21 Registered AP2 2 C9120AXI-B a4b2.3c11.2202 a4b2.3c44.5600 Floor 2 US 10.10.30.22 Registered
On an AireOS WLC, the same list is in the GUI under WIRELESS › Access Points › All APs, where you can also open an AP and change its AP Mode.
What goes wrong and how to troubleshoot it
| Symptom | Likely cause | Fix |
|---|---|---|
| AP never joins, no IP address | Port in the wrong VLAN, no DHCP scope, or no PoE | show interfaces status, show power inline, DHCP pool |
| AP has an IP but never joins | It can't find the WLC: no option 43, no DNS entry, WLC in another subnet | Add option 43 or the DNS name; check routing from VLAN 30 to VLAN 99 |
| AP finds the WLC but join fails | UDP 5246/5247 blocked by an ACL or firewall, or a certificate/time problem | Permit UDP 5246-5247; check the WLC clock (NTP) |
| AP keeps rebooting after joining | Downloading a new image (normal once) or software not supported by this WLC | Check the WLC release supports the AP model |
| FlexConnect clients get no address | Switch port is access instead of trunk, or VLANs missing | Make it a trunk and allow the client VLANs |
Common mistakes
- Configuring a trunk for a local-mode AP "to carry the SSIDs". The SSIDs travel inside CAPWAP; an access port is enough.
- Putting a FlexConnect AP that switches locally on an access port. Its client VLANs then never reach the switch.
- Blocking UDP 5246 and 5247 between AP and WLC subnets.
- Mixing up Monitor (radio listens for attacks) and Rogue detector (radio off, watches the wire).
- Thinking a cloud AP stops serving clients when the internet is down. Only management stops.
💡 Exam tip: expect questions on CAPWAP ports 5246 (control, DTLS) and 5247 (data), which functions belong to the AP and which to the WLC in split-MAC, and matching each AP mode to its job. Know that a local-mode AP uses an access port, while an autonomous AP with several VLANs and a locally switching FlexConnect AP use a trunk.
Key takeaways
- Autonomous APs work alone; lightweight APs depend on a WLC; cloud APs are managed from a dashboard.
- Split-MAC: the AP does real-time radio work, the WLC does management and policy.
- CAPWAP: UDP 5246 control (DTLS), UDP 5247 data, between AP and WLC IP addresses.
- APs find WLCs by broadcast, stored addresses, DHCP option 43 or DNS.
- Local mode tunnels client traffic to the WLC; FlexConnect can switch it locally.
Check yourself
A branch AP must keep serving clients and switch their traffic onto the branch LAN if the WAN link to the WLC fails. Which AP mode?
A firewall sits between the AP subnet and the WLC. Which traffic must it allow for CAPWAP?
In split-MAC, which task does the lightweight AP itself perform?
A local-mode AP serves two SSIDs mapped to VLANs 10 and 20. How should its switch port be configured?
An AP's radio is turned off and it looks for rogue APs by watching ARP on the wired network. Which mode is it in?