Back to Gyanamguru Training Portal

Enterprise Wireless Architecture & CAPWAP/802.1X Flow

Lightweight AP discovers Wireless LAN Controller, negotiates DTLS encryption, and builds CAPWAP tunnels

Status: Step 1 -> Lightweight AP sends CAPWAP Discovery Request to WLC over UDP 5246.

WLC CLI Console - Cisco Catalyst 9800 / AireOS Controller
WLC-9800# show ap summary
WLC-9800#

What is Centralized Wireless & 802.1X Authentication?

In a centralized enterprise network, Lightweight Access Points (LAPs) offload management, security, and roaming functions to a central Wireless LAN Controller (WLC). User authentication is offloaded to enterprise identity providers using 802.1X / EAP and RADIUS servers.

Core Wireless & Authentication Engine Architecture

Key Security & Authentication Terminology

Previous Lab (Next-Gen Firewall Simulation) Next Lab (Enterprise SD-WAN)
×

WLC Architecture Modes & Authentication Matrix

Active Mode: Split-MAC Centralized Controller Mode

802.1X EAP Authentication Protocol Comparison

EAP Type Inner Credentials Server Certificate Required Client Certificate Required
EAP-TLSMutual Digital CertificatesYesYes (High Security)
PEAPv0 (MSCHAPv2)Username / PasswordYesNo (Soft Credentials)
EAP-FASTPAC / Protected CredentialsOptionalNo
EAP-TTLSTunneled User CredentialsYesOptional

Essential Diagnostic Commands

View Connected Access Points: show ap summary

View Active Wireless Clients: show client summary

View Live 802.1X Authentication Trace: show auth-traceblock

View Configured WLAN SSIDs: show wlan summary