300-425 · Question #112
A customer called with a requirement that internal clients must be on different subnets depending on the building they are in All access points are operating in local mode and will not be modified…
The correct answer is A. Create AP groups for each desired location, map the correct VLANs to the internal SSlD and. AP groups allow a single SSID to map to different VLANs depending on which group an AP belongs to, enabling location-based subnet segmentation on a single controller.
Question
A customer called with a requirement that internal clients must be on different subnets depending on the building they are in All access points are operating in local mode and will not be modified, and this is a single controller solution. Which design approach creates the desired result?
Options
- ACreate AP groups for each desired location, map the correct VLANs to the internal SSlD and
- BCreate an SSID. place it to the desired VLAN under WLANs. and configure 802.ix in ISE to
- CCreate FiexConnect groups, place the access points in. and set the correct VLAN to SSlD
- DCreate mobility anchors for the SSID. and on the controller under the internal SSID. Create a
How the community answered
(22 responses)- A73% (16)
- B5% (1)
- C18% (4)
- D5% (1)
Why each option
AP groups allow a single SSID to map to different VLANs depending on which group an AP belongs to, enabling location-based subnet segmentation on a single controller.
AP groups on a Cisco WLC allow administrators to assign different VLAN mappings to the same SSID for each group. By placing APs from each building into separate AP groups and mapping the internal SSID to the building-specific VLAN within each group, clients automatically receive an IP address from the correct subnet based on which AP they associate with. This is the supported method for location-based VLAN assignment when APs operate in local mode on a single controller.
Configuring a single VLAN for the SSID under WLANs assigns all clients to the same subnet regardless of location, and 802.1x with ISE handles authentication, not per-building subnet assignment.
FlexConnect groups are specifically designed for APs operating in FlexConnect mode, not local mode, so this option does not apply to the described deployment.
Mobility anchors are used to tunnel guest client traffic to a designated anchor controller for policy enforcement, not to assign different subnets to internal clients based on physical location.
Concept tested: AP groups for location-based VLAN mapping
Source: https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112553-ap-groups-vlan-00.html
Topics
Community Discussion
No community discussion yet for this question.