Two different building on a campus --> to different IP address ranges --> WLC1 and WLC2 ARE NOT in the same ip address range It will be a Layer 3 inter controller roam with anchor and foreign controller. The most recent platforms, such as the Catalyst 9800, transport mobility control messages over encrypted CAPWAP tunnels. Client data traffic is also transported over CAPWAP tunnels, but encryption is optional. Legacy controller platforms that are based on AireOS software prior to release 8.5 transport mobility messages over Ethernet-over-IP (EoIP) tunnels (IP protocol 97) and UDP port 16666. AireOS platforms running release 8.5 or later support encrypted CAPWAP. (16667)