Protection against unauthorized CAPWAP access from the WAN

The WLC or LANCOM router with activated WLC option handles CAPWAP requests from the LAN and the WAN in the same way. In the case of requests from WAN remote stations, it accepts the APs into its AP management and, under certain circumstances, it sends a default configuration. If configured appropriately, the CAPWAP service is no longer available to WAN remote stations, meaning that for WAN remote stations, APs are no longer accepted and configurations are not provisioned.

The configuration is done under WLAN Controller > General in the section Wireless LAN controller. If the automatic acceptance of new APs is enabled, you can use the feature Accept new AP over WAN connection to control whether the CAPWAP service is available to WAN remote stations.





No
The device accepts no new APs over the WAN connection.
Only via VPN
The device only accepts new APs if the WAN connection is via VPN.
Yes
The device accepts all new APs over the WAN connection.

www.lancom-systems.com

LANCOM Systems GmbH | A Rohde & Schwarz Company | Adenauerstr. 20/B2 | 52146 Wuerselen | Germany | E‑Mail info@lancom.de

LANCOM Logo