CAPWAP

原文地址:https://en.wikipedia.org/wiki/Capwap

 

CAPWAP

From Wikipedia, the free encyclopedia
  (Redirected from Capwap)
Jump to: navigation, search

CAPWAP stands for Control And Provisioning of Wireless Access Points. The protocol specification is described in RFC 5415 and an IEEE 802.11 binding is provided in RFC 5416 and is based on LWAPP (Lightweight Access Point Protocol).

CAPWAP is a standard, interoperable protocol that enables a controller to manage a collection of wireless access points, and uses UDP ports 5246 (control channel) and 5247 (data channel).

The state machine of CAPWAP is similar to LWAPP's, but with the addition of a full Datagram Transport Layer Security (DTLS) tunnel establishment. The standard provides configuration management and device management, allowing for configurations and firmware to be pushed to access points (APs). Because the overall state design of the CAPWAP protocol is largely the same as the finite state machine (FSM) in LWAPP, a detailed diagram is not needed.

This protocol differentiates between data traffic and control traffic, as LWAPP did. However, only the control messages are transmitted in a DTLS tunnel. The publishers argue that an unencrypted data channel is not a security threat, because full IPsec is available. More consideration has been placed on ensuring that CAPWAP is secure, by taking advantage of the security offered by requiring full encryption with authentication between the controller and AP. This creates some inconveniences, however, in that both APs and controllers need to be preconfigured in order to associate with each other. Both the AP and controller must be either loaded with PSKs or certificate files to enable encrypted communication.

Access Control Lists are also implemented to prevent rogue CAPWAP controllers from hijacking unassociated APs.

[edit] See also

[edit] External links


 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值