nerdexam
Cisco

300-365 · Question #161

An organization is planning on concerting remote offices to FlexConnect to centralize their Cisco WLCs. When preparing the Cisco ACLs for the new deployment, which three restrictions must the…

The correct answer is A. FlexConnect ACLs only B. up to 64 rules per ACL E. all rules applied inbound only. FlexConnect ACLs have specific constraints that differ from standard WLC ACLs, including rule count limits, ACL type restrictions, and directional enforcement rules.

Wireless Deployment

Question

An organization is planning on concerting remote offices to FlexConnect to centralize their Cisco WLCs. When preparing the Cisco ACLs for the new deployment, which three restrictions must the engineer keep in mind? (Choose three.)

Options

  • AFlexConnect ACLs only
  • Bup to 64 rules per ACL
  • Cup to 32 rules per ACL
  • DFlexConnect or standard ACLs
  • Eall rules applied inbound only
  • Fall rules applied in both directions

How the community answered

(44 responses)
  • A
    84% (37)
  • C
    9% (4)
  • D
    5% (2)
  • F
    2% (1)

Why each option

FlexConnect ACLs have specific constraints that differ from standard WLC ACLs, including rule count limits, ACL type restrictions, and directional enforcement rules.

AFlexConnect ACLs onlyCorrect

FlexConnect deployments require FlexConnect-specific ACLs because standard WLC ACLs are not pushed to or enforced by the FlexConnect AP when traffic is locally switched at the branch.

Bup to 64 rules per ACLCorrect

FlexConnect ACLs support a maximum of 64 rules per ACL, which engineers must account for when designing access policy for branch office deployments.

Cup to 32 rules per ACL

The per-ACL rule limit for FlexConnect is 64, not 32, so this understates the actual capacity available to the engineer.

DFlexConnect or standard ACLs

Standard WLC ACLs are not supported in FlexConnect mode for locally switched traffic; only FlexConnect-specific ACLs are applicable.

Eall rules applied inbound onlyCorrect

FlexConnect ACLs are applied inbound only on the AP, meaning traffic is inspected as it enters the AP interface but not as it exits, which limits bidirectional enforcement capability.

Fall rules applied in both directions

FlexConnect ACLs are enforced inbound only, not in both directions, making bidirectional enforcement unsupported in this deployment model.

Concept tested: FlexConnect ACL restrictions and limitations

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/flexconnect.html

Topics

#FlexConnect ACLs#ACL rules#FlexConnect deployment#access control

Community Discussion

No community discussion yet for this question.

Full 300-365 Practice