300-365 · Question #109
Branch wireless users report that they can no longer access services from head office but can access services locally at the site. New wireless users can associate to the wireless while the WAN is…
The correct answer is B. standalone mode D. WPA2 personal E. authentication-local/switch-local. When the WAN link to the WLC is down, FlexConnect APs enter standalone mode and can still allow client associations using locally configured credentials such as WPA2 Personal, performing both authentication and switching locally.
Question
Branch wireless users report that they can no longer access services from head office but can access services locally at the site. New wireless users can associate to the wireless while the WAN is down. Which three options (Cisco FlexConnect state, operation mode, and authentication method) are seen in this scenario? (Choose three.)
Options
- Aauthentication-central/switch-local
- Bstandalone mode
- Cauthentication-central/switch-central
- DWPA2 personal
- Eauthentication-local/switch-local
- FWPA2 enterprise
How the community answered
(49 responses)- A8% (4)
- B69% (34)
- C18% (9)
- F4% (2)
Why each option
When the WAN link to the WLC is down, FlexConnect APs enter standalone mode and can still allow client associations using locally configured credentials such as WPA2 Personal, performing both authentication and switching locally.
Authentication-central/switch-local requires the WLC to handle authentication, which is unavailable when the WAN link is down.
Standalone mode is the FlexConnect state that activates when the AP loses connectivity to the WLC - the AP continues to service clients using cached configuration without the controller.
Authentication-central/switch-central requires both authentication and data switching through the WLC via the WAN tunnel, which is not possible in this scenario.
WPA2 Personal (PSK) uses a locally stored pre-shared key, allowing the AP to authenticate new clients entirely without contacting the WLC or a RADIUS server, which explains why new users can still associate while the WAN is down.
Authentication-local/switch-local is the FlexConnect operation mode active in standalone mode with PSK - the AP performs the authentication itself and also locally switches client data traffic, consistent with local service access but no head-office reachability.
WPA2 Enterprise requires a RADIUS server (typically reachable only via the WAN) to authenticate clients; new clients could not associate if WPA2 Enterprise were in use with the WAN down.
Concept tested: FlexConnect standalone mode and local authentication
Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/flexconnect.html
Topics
Community Discussion
No community discussion yet for this question.