nerdexam
Cisco

300-365 · Question #89

A security engineer wants all guest users to be terminated on the DMZ of their firewall. Which two configurations must be implemented to fulfill this new requirement? (Choose two.)

The correct answer is B. UDP ports 16666 and IP protocol 97 on the firewall C. a mobility group with a controller in an isolated network on the firewall. Anchoring guest traffic to a DMZ controller requires opening the correct firewall ports for the EoIP mobility tunnel and configuring a mobility anchor relationship with a controller in the isolated DMZ network.

Guest Access Deployment

Question

A security engineer wants all guest users to be terminated on the DMZ of their firewall. Which two configurations must be implemented to fulfill this new requirement? (Choose two.)

Options

  • ATCP port 16666 and 16113 in an ACL on the controller
  • BUDP ports 16666 and IP protocol 97 on the firewall
  • Ca mobility group with a controller in an isolated network on the firewall
  • Dan RF group with a controller in an isolated network on the firewall
  • EUDP ports 1812 and 1645 in an ACL on the controller

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    49% (23)
  • D
    28% (13)
  • E
    17% (8)

Why each option

Anchoring guest traffic to a DMZ controller requires opening the correct firewall ports for the EoIP mobility tunnel and configuring a mobility anchor relationship with a controller in the isolated DMZ network.

ATCP port 16666 and 16113 in an ACL on the controller

TCP is not used for the EoIP mobility tunnel; the correct transport is UDP 16666 combined with IP protocol 97, not TCP ports 16666 and 16113.

BUDP ports 16666 and IP protocol 97 on the firewallCorrect

The EoIP (Ethernet over IP) mobility tunnel between a foreign controller and the guest anchor controller uses UDP port 16666 for mobility control messages and IP protocol 97 for the actual data encapsulation; these must be permitted on the firewall between the two controllers.

Ca mobility group with a controller in an isolated network on the firewallCorrect

A mobility group relationship must be established between the internal foreign controller and the guest anchor controller placed in the DMZ, so that the WLC can tunnel guest client traffic to the anchor where it terminates on the DMZ segment.

Dan RF group with a controller in an isolated network on the firewall

An RF group coordinates RF management such as DCA and TPC between controllers and has no role in guest traffic anchoring or firewall traversal.

EUDP ports 1812 and 1645 in an ACL on the controller

UDP ports 1812 and 1645 are standard RADIUS authentication and accounting ports and are not required for the inter-controller EoIP mobility tunnel.

Concept tested: Guest anchor controller DMZ deployment and firewall ports

Source: https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/107606-guest-anchor-config.html

Topics

#guest access#DMZ#mobility group#firewall configuration

Community Discussion

No community discussion yet for this question.

Full 300-365 Practice