Which CAPWAP UDP ports must be open for AP-WLC communication?

Wireless Networking

A Cisco administrstor deploys a new wireless network but CAPWAP APs cannot communicate with the wireless controller. IP connectivity in the network functions properly. Which action resolves the issue?

  1. Open CAPWAP UDP port 12222 in the network firewall.
  2. Open CAPWAP UDP ports 5246 and 5247 in the network firewall. Source Reference Answer
  3. Enable the UDP Lite feature on the WLC.
  4. Ensure that the controller is connected to a AAA server.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of CAPWAP transport ports, and the common trap is confusing them with legacy LWAPP ports (12222/12223) or assuming TCP is used.

CAPWAP uses UDP 5246 for control and UDP 5247 for data between lightweight APs and the WLC; community consensus confirms that firewalls blocking these ports prevent AP join.

Option A (UDP 12222) is the most popular wrong answer because 12222 was the control port for legacy LWAPP, not CAPWAP.

Community Discussion (4 comments)

chiacche 👍 2 Selected: B
-> UDP port 5246 is used for CAPWAP control traffic. -> UDP port 5247 is used for CAPWAP data traffic. If these ports are blocked, the APs will not be able to establish a CAPWAP tunnel with the controller, which is necessary for communication between the APs and the WLC.
slacker_at_work 👍 2 Selected: B
CAPWAP uses UDP ports 5246 (control channel) and 5247 (data channel).
shefo1 👍 4 Selected: B
UDP ports 5246 and 5247 are the designated ports for CAPWAP control and data traffic, respectively. If these ports are blocked by a firewall, the APs cannot establish a connection with the WLC.
peugeotdude 👍 3 Selected: B
Those are the correct port numbers

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

CAPWAP (Control and Provisioning of Wireless Access Points) uses UDP port 5246 for the control channel and UDP port 5247 for the data channel between lightweight APs and the WLC. If IP connectivity is verified but APs still cannot join, a firewall is almost certainly blocking one or both of these UDP ports. Opening 5246 and 5247 on every intermediate device restores the CAPWAP tunnel.

Why the Other Options Are Wrong

Option A references UDP 12222, which was the LWAPP control port used on older WLC software and is no longer relevant for CAPWAP. Option C (UDP Lite) is an optional encapsulation feature that does not replace the need for the standard CAPWAP ports to be reachable. Option D (AAA server) is unrelated to the AP-to-WLC discovery and join process; AAA is only consulted after the tunnel is established for client authentication.

Community Comment Notes

Comments uniformly reinforce that 5246 is the control channel and 5247 is the data channel, with multiple contributors explicitly contrasting these with the legacy LWAPP port 12222. The 100% vote for option B shows strong community alignment, and several comments highlight the firewall as the typical culprit when IP reachability is confirmed but CAPWAP fails.

Official Reference

Exam Strategy

Memorize CAPWAP as UDP 5246 (control) and 5247 (data), and immediately flag any option mentioning 12222 or 12223 as a legacy LWAPP distractor on the ENCOR and ENARSI exams.

Related Analysis

Practice All 350-401 Questions

Access 218 questions with complete answers and detailed explanations.

View Full 350-401 Practice Test →

← Back to 350-401 Study Guide