nerdexam
Cisco

200-301 · Question #1462

Which selections must be used on the WLC when implementing a RADIUS server for wireless authentication?

The correct answer is C. AAA Override and the IP address of the server. To implement RADIUS server authentication for wireless clients on a Wireless LAN Controller (WLC), you must configure the RADIUS server's IP address and enable AAA Override for the WLAN.

Submitted by daniela_cl· Mar 5, 2026Network Access

Question

Which selections must be used on the WLC when implementing a RADIUS server for wireless authentication?

Options

  • AClient Exclusion and SSH
  • BNetwork Access Control State and SSH
  • CAAA Override and the IP address of the server
  • D802.1x and the MAC address of the server

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    93% (26)

Why each option

To implement RADIUS server authentication for wireless clients on a Wireless LAN Controller (WLC), you must configure the RADIUS server's IP address and enable AAA Override for the WLAN.

AClient Exclusion and SSH

Client Exclusion is a security feature that temporarily blocks clients exhibiting suspicious behavior, and SSH is a secure remote management protocol; neither is directly used for enabling RADIUS authentication on a WLAN.

BNetwork Access Control State and SSH

Network Access Control State relates to NAC features, and SSH is for secure management; neither directly configures RADIUS authentication for wireless clients.

CAAA Override and the IP address of the serverCorrect

When configuring a RADIUS server for wireless authentication on a WLC, you need to specify the IP address of the RADIUS server so the WLC knows where to send authentication requests. AAA Override allows the RADIUS server to dynamically apply specific client-level policies, such as VLANs or ACLs, after successful authentication, which is a common and important feature when integrating with RADIUS.

D802.1x and the MAC address of the server

While 802.1X is the standard for port-based network access control often used with RADIUS, you configure the RADIUS server by its IP address on the WLC, not its MAC address, which is a Layer 2 identifier.

Concept tested: WLC RADIUS configuration

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/wlan_security.html#concept_E77494E69F214A4DAA2B3C52F53E8797

Topics

#WLC configuration#RADIUS integration#Wireless authentication#AAA Override

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice