nerdexam
Cisco

300-365 · Question #122

An engineer has all of the remote locations using a pair of FlexConnect WLCs with locally switched WLANs and must leverage local certificate based authentication. Which component must be configured?

The correct answer is A. Configure the APs in FlexConnect Central Auth. This question tests understanding of FlexConnect authentication modes required to support certificate-based (EAP-TLS) authentication when WLANs are locally switched at remote sites.

WLAN Security Deployment

Question

An engineer has all of the remote locations using a pair of FlexConnect WLCs with locally switched WLANs and must leverage local certificate based authentication. Which component must be configured?

Options

  • AConfigure the APs in FlexConnect Central Auth.
  • BManually install certificates on access points.
  • CUpload the vendor certificate to the Cisco WLC.
  • DCisco WLC must be integrated with LDAP.

How the community answered

(26 responses)
  • A
    73% (19)
  • B
    8% (2)
  • C
    15% (4)
  • D
    4% (1)

Why each option

This question tests understanding of FlexConnect authentication modes required to support certificate-based (EAP-TLS) authentication when WLANs are locally switched at remote sites.

AConfigure the APs in FlexConnect Central Auth.Correct

Configuring APs in FlexConnect Central Auth mode allows the AP to act as an 802.1X authenticator while forwarding EAP exchanges to the WLC, which communicates with the central RADIUS server - this is required for certificate-based EAP methods like EAP-TLS to function in a FlexConnect locally switched WLAN deployment.

BManually install certificates on access points.

Manually installing certificates on APs is not a supported or required step for enabling certificate-based client authentication in FlexConnect mode.

CUpload the vendor certificate to the Cisco WLC.

Uploading a vendor certificate to the WLC is not the configuration needed to enable local certificate-based authentication for FlexConnect locally switched WLANs.

DCisco WLC must be integrated with LDAP.

LDAP integration with the WLC supports username/password authentication lookups and does not provide certificate-based EAP authentication for FlexConnect deployments.

Concept tested: FlexConnect Central Auth for certificate-based EAP authentication

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/flexconnect.html

Topics

#FlexConnect#local authentication#certificate authentication#Central Auth

Community Discussion

No community discussion yet for this question.

Full 300-365 Practice