On the 9800 WLC, control plane encryption is always enabled, which means that you need to have secure mobility enabled on the AireOS side. However, data link encryption is optional. If you enable it on the 9800 side, enable it on AireOS with: config mobility group member data-dtls enable. https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless- controllers/213913-building-mobility-tunnels-on-catalyst-98.html