300-365 · Question #35
A customer requires wireless traffic from the branch to be routed through the firewall at corporate headquarters. There is a RADIUS server in each branch location. Which FlexConnect state should be…
The correct answer is C. central authentication and central switching. When all branch wireless traffic must traverse the corporate HQ firewall, FlexConnect central authentication and central switching is required because it tunnels both data and authentication traffic back through the WLC at headquarters.
Question
A customer requires wireless traffic from the branch to be routed through the firewall at corporate headquarters. There is a RADIUS server in each branch location. Which FlexConnect state should be used in this scenario?
Options
- Alocal authentication and local switching
- Blocal authentication and central switching
- Ccentral authentication and central switching
- Dcentral authentication and local switching
How the community answered
(62 responses)- A6% (4)
- B3% (2)
- C76% (47)
- D15% (9)
Why each option
When all branch wireless traffic must traverse the corporate HQ firewall, FlexConnect central authentication and central switching is required because it tunnels both data and authentication traffic back through the WLC at headquarters.
Local authentication and local switching keeps both RADIUS exchanges and data switching at the branch, meaning traffic never reaches the corporate HQ firewall and the primary requirement is unmet.
Local authentication and central switching would use the branch RADIUS server for authentication while tunneling data to HQ, creating split policy enforcement and inconsistently satisfying the full central control requirement.
Central switching encapsulates all client data frames in CAPWAP and forwards them to the WLC at corporate headquarters before routing onward, ensuring every data packet passes through the HQ firewall as required. Central authentication routes all 802.1X and RADIUS exchanges through the central WLC as well, providing consistent policy enforcement at HQ even though a local RADIUS server exists at the branch.
Central authentication and local switching authenticates users at HQ but bridges data traffic locally at the branch interface, so client data does not pass through the corporate HQ firewall as required.
Concept tested: FlexConnect mode selection for centralized firewall enforcement
Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-8/b_FlexConnect_Deployment_Guide.html
Topics
Community Discussion
No community discussion yet for this question.