Which Tunnel Enables Seamless L3 Roaming Between Cisco WLCs?

Wireless LAN Controller Architecture & Mobility

Which tunnel type allows clients to perform a seamless Layer 3 roam between a Cisco AireOS WLC and a Cisco IOS XE WLC?

  1. CAPWAP Source Reference Answer
  2. IPsec
  3. VPN
  4. Ethernet over IP

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the specific protocol governing mobility tunnels, with the primary trap being the legacy assumption that Ethernet-over-IP (EoIP) is universally required for WLC-to-WLC communication.

This question evaluates understanding of inter-controller mobility tunnel protocols required for seamless Layer 3 client roaming across different Cisco WLC platforms. The community overwhelmingly agrees that CAPWAP is the correct mechanism when bridging AireOS and IOS XE controllers.

Candidates frequently select Ethernet over IP (Option D) based on older Airespace/AireOS documentation stating that dual-AireOS deployments use EoIP for mobility. They overlook the critical architectural shift where cross-platform compatibility (AireOS to IOS XE/C9800) explicitly requires CAPWAP instead.

Community Discussion (5 comments)

matass_md 👍 1 Selected: D
CAPWAP is used between AP and WLC , Tunnels between 2 WCL = EoIP Ethernet Over IP
ExamTaker1017 👍 2 Selected: A
This document clears up this question and question 914. The tunnel is called a "mobility tunnel" but only CAPWAP can be used between 9800 and AireOS WLCs. Two AireOS WLCs must use EoIP instead of CAPWAP, but the tunnel is still a "mobility" tunnel (why Q914 can't be A:CAPWAP and must be C:mobility). https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-8/b_c9800_wireless_controller-aireos_ircm_dg.pdf
cjoyce1980 👍 1 Selected: A
A. CAPWAP (Control and Provisioning of Wireless Access Points) Explanation: CAPWAP is the protocol used for communication between access points and wireless controllers. It encapsulates both control and data traffic, enabling seamless roaming between access points, even across different Layer 3 networks. During Layer 3 roaming between a Cisco AireOS WLC and a Cisco IOS XE WLC, CAPWAP tunnels help maintain the client session without requiring reauthentication or disruption. Other options (IPsec, VPN, Ethernet over IP) are not designed for seamless roaming in the context of wireless controller-client communication.
chiacche 👍 1 Selected: A
Key : L3 tunnel for roaming → CAPWAP
Mistwalker 👍 2 Selected: A
"A Layer 3 intercontroller roam involves building an additional CAPWAP tunnel between the client’s initial WLC and the WLC to which it has roamed. The tunnel transmits the data to and from the client just like it is still associated with the original IP subnet and WLC. When a Layer 3 roam happens, the original WLC is called the anchor controller, and the current WLC where the roamed client is reassociated is called the foreign controller. The client is anchored to the original WLC even if it roams to different controllers." https://study-ccnp.com/wlan-intercontroller-layer-2-layer-3-roaming/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Inter-Controller Mobility Tunnels

When a wireless client moves across different subnets (Layer 3 boundaries) while maintaining its session, Cisco wireless controllers establish a dedicated mobility tunnel between the anchor controller (original) and the foreign controller (new location). This tunnel ensures the client retains its original IP address and subnet association, enabling a truly seamless roaming experience.

Protocol Selection: CAPWAP vs. EoIP

Historically, native AireOS WLCs communicated using Ethernet-over-IP (EoIP) for these mobility tunnels. However, Cisco modernized this architecture for interoperability. As noted by community experts, when integrating a legacy AireOS WLC with a modern Cisco IOS XE (Catalyst 9800) WLC, the platform automatically negotiates and establishes a CAPWAP tunnel instead of EoIP. This cross-platform requirement makes CAPWAP the definitive answer for mixed-environment deployments.

Why Other Options Are Incorrect

  • IPsec and VPN are security protocols used for encrypted site-to-site or remote-access connections, not for internal controller mobility data forwarding.
  • Ethernet over IP (EoIP) is functionally correct only when connecting two identical AireOS WLCs. It lacks the necessary feature parity and negotiation capabilities required when pairing AireOS with IOS XE hardware/software stacks.
As highlighted in community discussion, the exam deliberately tests your awareness of this platform-specific evolution rather than legacy single-vendor behavior.

Official Reference

Exam Strategy

Always map the question's hardware/software combinations to their specific protocol requirements before selecting an answer. For Cisco wireless mobility questions, remember that pure AireOS environments rely on EoIP, but any deployment involving IOS XE or Catalyst 9800 controllers mandates CAPWAP for mobility tunnels.

Related Analysis

Practice All 350-401 Questions

Access 218 questions with complete answers and detailed explanations.

View Full 350-401 Practice Test →

← Back to 350-401 Study Guide