Routelearn.net
Course menu

Course 7: Wireless for CCNALesson 2.1 (2 of 4 in this course)47 of 91 in the CCNA series

Autonomous, lightweight and cloud APs

Autonomous APs, lightweight APs with a WLC and CAPWAP, cloud-managed APs, split-MAC and the AP modes.

Intermediate · 12 min read

A wireless LAN architecture is the model that decides where an access point’s control and management functions live. Autonomous APs are configured and run independently, lightweight APs share the work with a Wireless LAN Controller (WLC) over CAPWAP tunnels in a split-MAC design, and cloud-managed APs are configured and monitored from a cloud dashboard.

In simple terms: Each access point can be managed on its own, by a central controller, or from a website in the cloud. The architecture is simply the choice of who is in charge of the APs.

A real-life situation

A school has 60 access points. Each one was set up by hand. Now the guest password must change, and someone has to log in to 60 APs, one by one. Halfway through, half the APs have the new password and half the old one. Teachers roaming between classrooms keep losing Wi-Fi.

The fix is to manage all APs from one place. That is what this lesson is about: the three ways enterprise APs are built and managed, how lightweight APs talk to a controller, and the AP modes the CCNA expects you to know.

What the three architectures are

ArchitectureWho controls the APWhere client traffic goesGood for
AutonomousEach AP on its own (its own CLI or GUI)Bridged straight onto the AP's switch port, one VLAN per SSIDA few APs, a home or small office
Lightweight + WLCA Wireless LAN Controller (WLC), through CAPWAPTunnelled to the WLC in CAPWAP (local mode), or switched locally (FlexConnect)Campuses with many APs
Cloud-managed (e.g. Cisco Meraki)A dashboard in the cloudBridged locally at the AP; only management goes to the cloudMany small sites, little IT staff

An autonomous AP is a complete device: it runs its own configuration, security and RF settings. An AP with two SSIDs mapped to two VLANs needs an 802.1Q trunk to its switch. Roaming between autonomous APs is slower because each one works alone.

A lightweight AP (LAP) can't work on its own. It downloads its configuration and software from a WLC and does only the time-critical work itself.

A cloud-managed AP is configured from a web dashboard. If the internet link fails, the AP keeps serving clients with its last settings, but you can't change anything until the link returns.

Why split-MAC: who does what

The 802.11 standard defines a lot of work at the MAC layer. Some of it must happen within microseconds, right at the radio. Some of it is about policy and the big picture. Cisco splits the two. This is called split-MAC:

Lightweight AP (real-time)WLC (management)
Sending beacons and answering probesClient authentication (with RADIUS) and association
Sending ACKs and retransmitting framesSecurity policy, QoS policy, WLAN to VLAN mapping
Queueing and prioritising framesRoaming between APs
Encrypting and decrypting on the airRF management (channels and power, RRM)
MAC-layer handling of the radioAP software images and configuration

Because the WLC sees every AP and every client, it can choose channels for all APs together, keep a client's session when it roams, and push one change to all APs at once.

How CAPWAP carries the traffic

The AP and WLC talk with CAPWAP (Control And Provisioning of Wireless Access Points, RFC 5415). It is an open standard based on Cisco's older LWAPP. CAPWAP builds two tunnels between the AP's IP address and the WLC's management IP address:

  • Control tunnel, UDP 5246: AP configuration, software, radio settings. Always encrypted with DTLS (TLS over UDP).
  • Data tunnel, UDP 5247: client frames. Not encrypted by default.

Because CAPWAP runs over IP, the AP and WLC can be in different subnets, even different buildings. In the lab, AP1 is in VLAN 30 (10.10.30.21) and WLC1 is in VLAN 99 (10.10.99.10); SW1 routes between them.

SSID StaffGi1/0/10VLAN 30Gi1/0/1-2Po1 trunkGi1/0/20VLAN 99LaptopStaff · 10.10.10.50AP110.10.30.21SW1gateway .1 for each VLANWLC1mgmt 10.10.99.10RADIUS10.10.99.50
  1. 1. The laptop sends a frame to AP1. It is encrypted on the air with WPA2 or WPA3. AP1 decrypts it.
  2. 2. AP1 tunnels it to WLC1. AP1 wraps the frame in CAPWAP, UDP 5247 and an IP header from 10.10.30.21 to 10.10.99.10. SW1 just routes a UDP packet.
  3. 3. WLC1 puts it on the client VLAN. WLC1 removes the tunnel and sends the frame out its trunk tagged VLAN 10, the VLAN mapped to the Staff WLAN. SW1 (10.10.10.1) routes it on.
  4. 4. Control traffic uses the other tunnel. Configuration and radio settings flow on UDP 5246, protected by DTLS.
A client frame inside the CAPWAP data tunnel

AP1 (10.10.30.21) → SW1 → WLC1 (10.10.99.10). The switches route and switch an ordinary UDP packet; only the WLC opens it.

EthernetAP MAC → gateway MAC
Outer IP10.10.30.21 → 10.10.99.10
UDPdst port 5247 (data)
CAPWAPtunnel header
Client 802.11 framelaptop 10.10.10.50 → web server
added by AP1 (the tunnel)what the laptop sent
Control tunnel · UDP 5246
Join, configuration, firmware, radio settings. Always encrypted with DTLS.
Data tunnel · UDP 5247
Client traffic. Not encrypted by default; DTLS for data can be turned on.
In local mode, every client frame crosses the network inside CAPWAP. This is why a local-mode AP needs only one VLAN on its switch port.

How an AP finds and joins a WLC

A new lightweight AP boots with no idea where its controller is. It first gets an IP address (usually by DHCP), then looks for WLCs in this order of methods:

  1. Broadcast a discovery request on its local subnet (works only if a WLC is in the same subnet).
  2. WLC addresses it learned before (stored in the AP's memory), and addresses of other WLCs in the same mobility group.
  3. DHCP option 43: the DHCP server hands out the WLC's IP address.
  4. DNS: the AP looks up CISCO-CAPWAP-CONTROLLER.<domain> using the domain name it got from DHCP.
  5. Primary, secondary and tertiary WLCs configured on the AP itself (once it has joined before).

From all the answers, the AP picks a WLC: first a configured primary controller, otherwise the least-loaded one. Then the join begins:

Step 1 of 7 · DHCP (with option 43)
AP1
10.10.30.21
SW1
DHCP server
WLC1
10.10.99.10

1. DHCP (with option 43) · AP ↔ DHCP · UDP 68 ↔ 67

AP1 gets 10.10.30.21, gateway 10.10.30.1, and option 43 pointing to 10.10.99.10.

AP1 registered
Mode:
Local
Controller:
WLC1 10.10.99.10
Tunnels:
Control 5246 (DTLS), data 5247
An AP joining a WLC: discovery, DTLS, join, then download of image and configuration.

WLC deployment options

The controller itself can live in different places:

DeploymentWhere the WLC runsTypical size
Unified (centralized)A hardware appliance in the data centre or coreLarge campus, up to thousands of APs
Cloud-basedA virtual WLC (e.g. Catalyst 9800-CL) in a private or public cloudMedium to large
EmbeddedSoftware inside an access-layer switchBranch, small campus
Inside an APOne AP also acts as the controller (Mobility Express, or Embedded Wireless Controller on Catalyst 9100 APs)Small sites, around 100 APs or fewer

AP modes

A lightweight AP can be put in one of several modes from the WLC. The CCNA lists these:

ModeWhat the AP does
LocalThe default. Serves clients and tunnels all their traffic to the WLC. Briefly scans other channels for rogues and RRM data.
FlexConnectServes clients and can switch their traffic locally onto the branch switch, so it doesn't cross the WAN. Keeps working if the WAN link to the WLC goes down.
MonitorDoesn't serve clients. Listens on all channels for rogue APs, attacks (IDS) and location tracking.
SnifferCaptures 802.11 frames on one channel and sends them to a PC running a packet analyser like Wireshark.
Rogue detectorRadio off. Watches the wired network (ARP) to find rogue APs plugged into your switches.
SE-ConnectSpectrum Expert: a spectrum analyser that finds non-Wi-Fi interference (microwaves, cameras).
Bridge / MeshBuilds wireless links to other APs, point-to-point or mesh, to reach places with no cable.
Flex+BridgeFlexConnect and mesh together on one AP.

How to configure the switch ports on Cisco IOS

The AP itself is configured from the WLC, but the switch port it plugs into is yours. The right port type depends on the mode:

interface GigabitEthernet1/0/10 description AP1 (lightweight, local mode) switchport mode access switchport access vlan 30 spanning-tree portfast power inline auto

Local mode: an access port in the AP VLAN. Client VLANs are not needed here because client traffic is inside CAPWAP. PortFast lets the AP get an address quickly; PoE powers it.

interface GigabitEthernet1/0/11 description AP2 (FlexConnect, local switching) switchport mode trunk switchport trunk native vlan 30 switchport trunk allowed vlan 10,20,30 spanning-tree portfast trunk

FlexConnect with local switching (or an autonomous AP with several SSIDs): a trunk. The AP's own address is in the native VLAN 30; client traffic is tagged 10 and 20.

On the DHCP server for the AP VLAN, option 43 tells APs where WLC1 is. On a Cisco IOS DHCP server, the value is a hex string: type f1, length (4 bytes per WLC), then the WLC address in hex. 10.10.99.10 is 0a0a630a:

ip dhcp pool AP-VLAN30 network 10.10.30.0 255.255.255.0 default-router 10.10.30.1 option 43 hex f1040a0a630a

f1 = type, 04 = one WLC (4 bytes), 0a0a630a = 10.10.99.10. For two WLCs the length is 08 and both addresses follow.

How to verify it

On SW1, CDP shows the AP on its port. On a Catalyst 9800 WLC (IOS XE), show ap summary lists every joined AP:

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show cdp neighbors GigabitEthernet1/0/10
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
                  S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone

Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID
AP1              Gig 1/0/10        142             T I    C9120AXI- Gig 0
AP1 is physically connected to Gi1/0/10.
Example output · based on Cisco documentation; exact format varies by platform and software version
WLC1#show ap summary
Number of APs: 2

AP Name   Slots  AP Model      Ethernet MAC    Radio MAC       Location  Country  IP Address    State
-------------------------------------------------------------------------------------------------------
AP1       2      C9120AXI-B    a4b2.3c11.2201  a4b2.3c44.5500  Floor 1   US       10.10.30.21   Registered
AP2       2      C9120AXI-B    a4b2.3c11.2202  a4b2.3c44.5600  Floor 2   US       10.10.30.22   Registered
Registered means the AP completed the CAPWAP join. The IP address is the AP's own address (VLAN 30), not a client address.

On an AireOS WLC, the same list is in the GUI under WIRELESS › Access Points › All APs, where you can also open an AP and change its AP Mode.

What goes wrong and how to troubleshoot it

SymptomLikely causeFix
AP never joins, no IP addressPort in the wrong VLAN, no DHCP scope, or no PoEshow interfaces status, show power inline, DHCP pool
AP has an IP but never joinsIt can't find the WLC: no option 43, no DNS entry, WLC in another subnetAdd option 43 or the DNS name; check routing from VLAN 30 to VLAN 99
AP finds the WLC but join failsUDP 5246/5247 blocked by an ACL or firewall, or a certificate/time problemPermit UDP 5246-5247; check the WLC clock (NTP)
AP keeps rebooting after joiningDownloading a new image (normal once) or software not supported by this WLCCheck the WLC release supports the AP model
FlexConnect clients get no addressSwitch port is access instead of trunk, or VLANs missingMake it a trunk and allow the client VLANs

Common mistakes

  • Configuring a trunk for a local-mode AP "to carry the SSIDs". The SSIDs travel inside CAPWAP; an access port is enough.
  • Putting a FlexConnect AP that switches locally on an access port. Its client VLANs then never reach the switch.
  • Blocking UDP 5246 and 5247 between AP and WLC subnets.
  • Mixing up Monitor (radio listens for attacks) and Rogue detector (radio off, watches the wire).
  • Thinking a cloud AP stops serving clients when the internet is down. Only management stops.

💡 Exam tip: expect questions on CAPWAP ports 5246 (control, DTLS) and 5247 (data), which functions belong to the AP and which to the WLC in split-MAC, and matching each AP mode to its job. Know that a local-mode AP uses an access port, while an autonomous AP with several VLANs and a locally switching FlexConnect AP use a trunk.

Key takeaways

  • Autonomous APs work alone; lightweight APs depend on a WLC; cloud APs are managed from a dashboard.
  • Split-MAC: the AP does real-time radio work, the WLC does management and policy.
  • CAPWAP: UDP 5246 control (DTLS), UDP 5247 data, between AP and WLC IP addresses.
  • APs find WLCs by broadcast, stored addresses, DHCP option 43 or DNS.
  • Local mode tunnels client traffic to the WLC; FlexConnect can switch it locally.

Check yourself

Predict · scenario 1

A branch AP must keep serving clients and switch their traffic onto the branch LAN if the WAN link to the WLC fails. Which AP mode?

Predict · scenario 2

A firewall sits between the AP subnet and the WLC. Which traffic must it allow for CAPWAP?

Predict · scenario 3

In split-MAC, which task does the lightweight AP itself perform?

Predict · scenario 4

A local-mode AP serves two SSIDs mapped to VLANs 10 and 20. How should its switch port be configured?

Predict · scenario 5

An AP's radio is turned off and it looks for rogue APs by watching ARP on the wired network. Which mode is it in?

FAQ

Which ports does CAPWAP use?
UDP 5246 for the control tunnel and UDP 5247 for the data tunnel, both between the AP and the WLC. The control tunnel is always encrypted with DTLS; data encryption is optional.
Should a lightweight AP in local mode connect to an access port or a trunk?
An access port. All client traffic is tunnelled to the WLC inside CAPWAP, so the AP only needs one VLAN for its own IP address. FlexConnect APs that switch traffic locally and autonomous APs with several SSIDs need a trunk.
What is split-MAC?
The 802.11 MAC layer work is split between the AP and the WLC. The AP handles real-time tasks like beacons, ACKs and encryption on the air; the WLC handles management tasks like authentication, roaming, RF management and policy.