Lists the default ciphersuites used for CAPWAP-DTLS, AP priorities, platform exclusions, and configuration guidance.
If link encryption is enabled for secure data channel traffic, the COS AP (DTLS client) prioritizes DHE-RSA-AES128-SHA over the ECDHE or GCM ciphersuite.
-
The preference order of the ciphersuites during the DTLS handshake is important. You can set the priority order when configuring cipher suites using this feature.
-
When explicit ciphersuites are not configured, the default ciphersuites listed in the table apply.
| Security Mode | Ciphersuite |
| FIPS and non-FIPS | •TLS_RSA_WITH_AES_128_CBC_SHA • TLS_DHE_RSA_WITH_AES_128_CBC_SHA • TLS_DHE_RSA_WITH_AES_256_CBC_SHA • TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| WLANCC | •TLS_DHE_RSA_WITH_AES_128_CBC_SHA • TLS_DHE_RSA_WITH_AES_256_CBC_SHA • TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
This feature is supported on all variants of Cisco Catalyst 9800 Series Wireless Controllers and APs, except for Cisco Industrial Wireless 3702 AP.
Refer to the release notes for a list of supported controllers and APs for each release: https://www.cisco.com/c/en/us/support/wireless/catalyst-9800-series-wireless-controllers/products-release-notes-list.html.