300-365 · Question #57
A customer called into the support center with a problem ticket that involves wireless clients having to reauthenticate when they are walking around their office. After further investigation, it was…
The correct answer is D. Verify the access points are spread out between the primary and secondary controller and that. When clients reauthenticate during roaming in an N+1 controller deployment, the engineer must verify that APs are correctly distributed across controllers and that inter-controller roaming is properly configured.
Question
A customer called into the support center with a problem ticket that involves wireless clients having to reauthenticate when they are walking around their office. After further investigation, it was discovered that the customer has two controllers in an N+1 deployment. Which action must the engineer take to troubleshoot the issue?
Options
- AVerify that the wireless controllers are in the same mobility group and that the access points are
- BUnder the SSID, make sure that 802.1 Iris configured and running for the clients.
- CMake sure that the SSID has the authentication set to 802.1x with Cisco Centralized Key
- DVerify the access points are spread out between the primary and secondary controller and that
How the community answered
(24 responses)- A13% (3)
- B17% (4)
- C4% (1)
- D67% (16)
Why each option
When clients reauthenticate during roaming in an N+1 controller deployment, the engineer must verify that APs are correctly distributed across controllers and that inter-controller roaming is properly configured.
While mobility group membership is relevant, verifying AP distribution specifically addresses the roaming reauthentication symptom in an N+1 scenario - this choice is incomplete as stated.
802.1X on the SSID is an authentication method configuration, not a roaming-specific setting, and would not directly explain reauthentication triggered by physical movement between APs.
Cisco Centralized Key Management (CCKM) helps reduce reauthentication overhead but configuring it alone does not resolve the underlying inter-controller mobility trust issue causing the reauthentication.
In an N+1 deployment, if APs are not properly spread between the primary and secondary controller with correct mobility group configuration, clients roaming between APs on different controllers will be forced to reauthenticate because the controllers do not have a trusted mobility relationship to share session keys. Verifying AP distribution and mobility tunnel state is the first step to diagnose inter-controller roaming failures.
Concept tested: Inter-controller roaming and mobility group troubleshooting
Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/roaming.html
Topics
Community Discussion
No community discussion yet for this question.