300-365 · Question #5
An engineer used an interface group under the SSID configuration, but noticed that a test client is getting an IP assigned in a different VLAN from the DHCP server. Which two options override the…
The correct answer is C. AP group G. AAA override. Interface groups assign clients to VLANs at the SSID level, but AP group interface mappings and AAA override attributes returned by a RADIUS server can supersede this assignment.
Question
An engineer used an interface group under the SSID configuration, but noticed that a test client is getting an IP assigned in a different VLAN from the DHCP server. Which two options override the interface group configuration on the SSID? (Choose two.)
Options
- Astatic VLAN on client
- BACL
- CAP group
- Dstatic IP on client
- EMAC filtering
- FRF group
- GAAA override
How the community answered
(29 responses)- B7% (2)
- C59% (17)
- D10% (3)
- E21% (6)
- F3% (1)
Why each option
Interface groups assign clients to VLANs at the SSID level, but AP group interface mappings and AAA override attributes returned by a RADIUS server can supersede this assignment.
A static VLAN is a network infrastructure concept and cannot be set by or on a wireless client to influence the controller's VLAN assignment.
ACLs permit or deny traffic flows based on policy and have no role in determining which VLAN or interface a client is placed on.
AP groups allow per-AP-group interface or VLAN mappings that take precedence over the WLAN-level interface group, so any AP belonging to a group with a specific interface assignment will use that mapping instead of the SSID interface group.
A static IP on a client affects only the Layer 3 address and does not change the Layer 2 VLAN assignment made by the WLC.
MAC filtering controls whether a device is permitted to associate and does not influence which interface or VLAN the client is assigned to after association.
RF groups coordinate radio resource management between controllers and have no effect on VLAN or interface assignments for wireless clients.
AAA override enables a RADIUS server to return VLAN attributes such as Tunnel-Private-Group-ID during 802.1X or MAC authentication, dynamically overriding the WLAN interface group assignment on a per-client basis.
Concept tested: SSID interface group VLAN assignment overrides
Source: https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/69100-wlc-aaa-override-vlan.html
Topics
Community Discussion
No community discussion yet for this question.