CAPWAP is the protocol used to provision and manage lightweight access points in enterprise wireless networks, enabling centralized control through a wireless LAN controller. This content also covers split MAC architecture, DTLS encryption, and FlexConnect for controller failover scenarios.
CAPWAP & Wireless Protocols
There are some really cheap access points that are out there, and then there's some really expensive access points that are out there. So what makes the difference between these cheap access points and these expensive enterprise level access points?
Well, a consumer access point doesn't perform as well. It's meant to just connect to a few computers; it doesn't have the radio and the antenna capable of handling large amounts of data, where an enterprise one definitely is built more for a larger quantity of users to be able to connect to it, and better performance.
Another difference is the feature set of these two: you're going to get a lot more feature sets with these enterprise level access points.
Another thing that's different about it is how easy they are to manage. These are actually pretty easy to manage, and these can be a lot more complicated to set up. But once you set up the infrastructure to be able to support these access points, then deploying them can be very quick and easy, and one of those protocols, CAPWAP, will allow us to deploy these much easier.
Let's start out by talking about what a lightweight access point is. This is an example of a lightweight access point, and if you were to hold this you would say that is not lightweight, because it's actually pretty heavy. In fact, this is heavier than this device right here, which is not just an access point but also has a router and a switch and other functionality. But weight wise, this is a lot lighter than this access point right here.
So what does it mean by lightweight access point? Well, it's lightweight because this access point doesn't have all the functionality that allows your computer to communicate to the rest of the network. It only takes on certain functionality.
What I mean by that is, here we have a network right here, and you have a computer that connects into the wireless, and so there's obviously some communication that's happening between your computer and the wireless access point. But a lot of the functionality of a typical access point, or a typical wireless network, is carried out by this wireless controller. So traffic gets tunneled from the access point to this wireless controller, and that wireless controller then figures out what's going to happen to it. So these access points are lightweight because they don't perform all of the duties of a wireless network; they just perform a subset of those duties.
This sharing of duties between the lightweight access point and the controller is known as split MAC architecture. It's split MAC architecture because it's layer 2 that's being split amongst these two different devices. Really, your wireless access point is going to handle all of layer 1, but the MAC side of this, the layer 2 side of this, is going to be split, and your access point is going to handle certain parts of this communication, and then your controller is going to handle the other part of this communication.
So the access point does the beacon and probe to make the connection, it does the packet acknowledgment and retransmission, it does frame queuing and packet prioritization, things like quality of service, and the MAC layer data encryption and decryption is handled — and that's all handled between your user that's connecting to the access point and the access point. And then what's handled on the controller is the authentication, the association and the frame translation.
So what will happen is this connection is made on this layer 1 and half a layer 2, and then the communication to actually get out onto the network, and the authentication and association and frame translation, happens on the controller side of this.
Now, how do you provision a lightweight access point? Well, it needs to know where the controller is. It's reliant on the controller to provide its services. So there's a few different ways that we can tell this device right here how to connect to the controller.
But that's how these devices, when you connect them to the network, will automatically discover the controller, be able to load the firmware, update the firmware on these different devices, and then be able to automatically come up, and you can manage them then right on your controller.
That's where our two protocols come into play: lightweight access protocol, or LWAPP, and control and provisioning of wireless access points, or also known as CAPWAP protocols. These two protocols are used to provision and facilitate this communication that happens.
So lightweight access protocol is one of the original ones, and then CAPWAP is the new and improved one. So what is the difference between these two?
LWAPP is defined by RFC 5412 and was developed in 2005. There is no security — we'll talk about DTLS — but from a communication standpoint between the controller and the access point there's no security, no DTLS. And it uses much higher ports for their communication. Notice there is two ports: one of them is for management and one of them is for data, but there's two different ports there.
And then for CAPWAP there is a host of RFCs that actually define how CAPWAP works. It was developed in 2009, uses DTLS at least for the management traffic, and then it also has two ports, one of them for management and one of them for the data.
The traffic that's going between your users and the access point would be the typical wireless traffic, but the traffic that goes between the wireless access point and the controller does look a little different, and there once again are two different ports that facilitate this. So for instance, with CAPWAP, this is the one that has the management traffic that goes between these two devices, and the 5247 would be the data traffic.
DTLS is a form of encryption that happens on some of this traffic that goes back and forth. With the management traffic, we actually encrypt that traffic with DTLS. You can also encrypt the data traffic with DTLS as well, but by default it is not turned on for our data traffic, so the data traffic remains unencrypted, versus the management.
Now, one of the problems with this type of setup is it's all reliant on the wireless controller. If the wireless controller goes down, that means that no access points can communicate. There's some things we can do, like create redundancy with this wireless controller — we can have more than one that's operating — but even if that network gets cut off, you could be stuck with all of your access points going down. Obviously that's not desirable.
So we have something called Flex Connect. Flex Connect allows our wireless access points, our lightweight access points, to go into one of two different modes. One of those modes is connected: it could be connected, and that just means that it has access to this wireless LAN controller and is operating as normal. But it can go into a standalone mode if it does not find that wireless controller. It would go into a standalone mode, and then it takes on the functionality of this wireless LAN controller, so now these devices that are connecting to it can get directly onto the network, cutting out the middleman of this wireless LAN controller. So it does have some capabilities to heal itself with this Flex Connect, so that way it can still connect to the network in the event that your controller goes down.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →