exam questions

Exam 300-425 All Questions

View all questions & answers for the 300-425 exam

Exam 300-425 topic 1 question 83 discussion

Actual exam question from Cisco's 300-425
Question #: 83
Topic #: 1
[All 300-425 Questions]

A wireless engineer must design mobility between two buildings at a campus site. The engineer has one controller at each site. The engineer is investigating inter- controller CAPWAP data and control traffic. Which two ports must be open? (Choose two.)

  • A. 5246
  • B. 5247
  • C. 8443
  • D. 16666
  • E. 16667
Show Suggested Answer Hide Answer
Suggested Answer: DE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Faridtnx
Highly Voted 2 years ago
Selected Answer: DE
A/B are capwap ports for AP-WLC connection. The question is asking for WLC-WLC D and E is correct
upvoted 9 times
...
NetworkJoe
Highly Voted 1 year, 5 months ago
Selected Answer: DE
inter-controller roaming is using UDP/16666 and UDP/16667 CAPWAP tunnels.
upvoted 7 times
...
e9cc965
Most Recent 3 months, 3 weeks ago
Selected Answer: DE
The Cisco Catalyst 9800 Series Wireless Controller mobility tunnel is a CAPWAP tunnel with control path (UDP 16666) and data path (UDP 16667). The control path is DTLS encrypted by default. Data path DTLS can be enabled when you add the mobility peer.
upvoted 1 times
...
Farhad123
7 months, 2 weeks ago
D and E are correct
upvoted 2 times
...
4cde783
8 months, 1 week ago
Selected Answer: DE
The Cisco Catalyst 9800 Series Wireless Controller mobility tunnel is a CAPWAP tunnel with control path (UDP 16666) and data path (UDP 16667). The control path is DTLS encrypted by default. Data path DTLS can be enabled when you add the mobility peer. https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/mobility.html
upvoted 1 times
...
ShamsDimashki
9 months, 3 weeks ago
Selected Answer: AB
16666 and 16667 used for legacy platforms using EoIP
upvoted 1 times
...
All_ultrex
10 months, 2 weeks ago
Selected Answer: AB
A&B, just googled the answer, CAPWAP talks on these two ports for data and control
upvoted 1 times
All_ultrex
9 months, 3 weeks ago
Changing my answer to DE, CyborgXCZ has a great answer below. This is a mobility tunnel, there for it uses UDP 16666 and UDP 16667
upvoted 2 times
...
...
Bandito
1 year, 3 months ago
Selected Answer: DE
The only intercontroller CAPWAP ports are 16666 and 16667 https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113344-cuwn-ppm.html
upvoted 3 times
...
SakoTRG
1 year, 6 months ago
a+b is correct CAPWAP uses 5246 + 5247 for both APs + WLC 16666 is used with EoIP Legacy
upvoted 3 times
...
Araghas
2 years, 1 month ago
Update to below: https://community.cisco.com/t5/wireless/question-about-udp-16667/td-p/1399015
upvoted 1 times
...
Araghas
2 years, 1 month ago
"Ensure that the CAPWAP UDP ports 5246 and 5247 (similar to the LWAPP UDP ports 12222 and 12223) are enabled and are not blocked by an intermediate device that could prevent an access point from joining the controller." https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-6/config-guide/b_cg86/ap_connectivity_to_cisco_wlc.html#capwap
upvoted 1 times
...
CyborgXCZ
2 years, 3 months ago
Selected Answer: DE
Matrix Page https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113344-cuwn-ppm.html Source----Dest.------Protocol-----Dest. Port------Src. Port-----Description WLC--------WLC-------UDP------------16666-----------16666----------Mobility - non-secured WLC--------WLC-------UDP------------16666------------N/A-------------Mobility - secured - removed in 5.2 WLC -------AP----------UDP------------5246-5247-----N/A-------------CAPWAP Ctl/Data
upvoted 4 times
...
CyborgXCZ
2 years, 3 months ago
D & E As per this official Cisco Document https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/mobility_groups.html If you have a firewall b/w your mobility group members, open UDP port 16666 and IP protocol 97. If you are using encrypted mobility, open UDP port 5246 and 5247. If you are using New Mobility, UDP port 16666, 16667, and 16668 are used. For information about protocols and port numbers that must be used for management and operational purposes, see the Matrix Site Further more looking at the Matrix Page https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113344-cuwn-ppm.html Source Dest. Protocol Dest. Port Src. Port Description WLC WLC UDP 16666 16666 Mobility - non-secured WLC WLC UDP 16667 n/a Mobility - secured - removed in 5.2 WLC AP UDP 5246-5247 n/a CAPWAP Ctl/Data Since the question is related to controllers between each site (WLC < --- > WLC) then D & E is the most logical answer here.
upvoted 3 times
...
Gab99
2 years, 3 months ago
its not really clear https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-2/config-guide/b_wl_17_2_cg/mobility.html says: "The Cisco Catalyst 9800 Series Wireless Controller mobility tunnel is a CAPWAP tunnel with control path (UDP 16666) and data path (UDP 16667)" https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-8/config-guide/b_cg88/mobility_groups.html says: "If you have a firewall b/w your mobility group members, open UDP port 16666 and IP protocol 97. If you are using encrypted mobility, open UDP port 5246 and 5247."
upvoted 1 times
...
vigyory
2 years, 3 months ago
I think D&E. Based on Cisco ENWLSD book - UDP/5246-47 is used for CAPWAP traffic between AP and WLC (5246 for Controll, and 5247 for Data traffic) - this book says: Test mobility control messaging over UDP port 16666 mping <ip-address> So, I think the right answers are D&E
upvoted 1 times
...
peer1024
2 years, 4 months ago
Selected Answer: DE
Explanation: Two different building on a campus --> to different IP address ranges --> WLC1 and WLC2 ARE NOT in te same ip address range It will be a Layer 3 inter controller roam with anchor and foreign controller. The most recent platforms, such as the Catalyst 9800, transport mobility control messages over encrypted CAPWAP tunnels. Client data traffic is also transported over CAPWAP tunnels, but encryption is optional. Legacy controller platforms that are based on AireOS software prior to release 8.5 transport mobility messages over Ethernet-over-IP (EoIP) tunnels (IP protocol 97) and UDP port 16666. AireOS platforms running release 8.5 or later support encrypted CAPWAP. (16667) Reference: Cert. guide "CCNP Enterprise ENWLSD 300-425 ENWLSI 300-430 Official Cert Guide", page 169f and page 175
upvoted 3 times
...
Alonzo_Harris
2 years, 5 months ago
Selected Answer: AB
The answer is A & B CAPWAP Control Channel: Uses UDP port 5246 CAPWAP Data Channel: Uses port 5247 and encapsulates (tunnels) the client's 802.11 frames
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...