3.6.3. CAPWAP
CAPWAP (Control And Provisioning of Wireless Access Points) is the tunnel protocol between lightweight APs and the WLC. Everything flows through this tunnel—control messages, management, and optionally client data.
| Traffic Type | UDP Port | Encryption | Contents |
|---|---|---|---|
| Control | 5246 | DTLS (mandatory) | AP config, client handoff, management |
| Data | 5247 | DTLS (optional) | Client traffic (in Local mode) |
What happens when the WLC becomes unreachable: it depends on the AP mode, and this is the distinction the exam tests. A Local mode AP tunnels all client traffic to the controller, so when the tunnel drops there is nowhere for that traffic to go: clients are dropped and the AP starts hunting for a controller. A FlexConnect AP switches locally and enters standalone mode, where existing clients keep working and no configuration change is possible. That's why WLC redundancy matters. Some deployments use FlexConnect specifically so branches can survive WLC outages.
⚠️ Exam Trap: If CAPWAP ports (5246/5247 UDP) are blocked by a firewall between the AP and WLC, the AP can't join the controller. This is a common troubleshooting scenario.