300-425 · Question #157
An engineer designs a new wireless network that uses a Cisco Catalyst 9800 Series wireless controller. The controller must be in a DMZ. The internal network is to be at the main on-premises data…
The correct answer is B. Use AirOS code that supports encryption of the control plane on the 5520 WLC. On the 9800 WLC, control plane encryption is always enabled, which means that you need to have secure mobility enabled on the AireOS side. However, data link encryption is optional. If you enable it on the 9800 side, enable it on AireOS with: config mobility group member…
Question
An engineer designs a new wireless network that uses a Cisco Catalyst 9800 Series wireless controller. The controller must be in a DMZ. The internal network is to be at the main on-premises data center of the customer. In addition, the customer wants to establish an EoIP tunnel to a Cisco 5520 WLC that is in a regional office. How must this requirement be incorporated into the design?
Options
- AUse Cisco IOS-XE code that supports encryption of the data plane on the Catalyst 9800 WLC.
- BUse AirOS code that supports encryption of the control plane on the 5520 WLC.
- CUse Cisco IOS-XE code that supports encryption of the control plane on the Catalyst 9800 WLC.
- DUse AirOS code that supports encryption of the data plane on the 5520 WLC.
How the community answered
(45 responses)- A22% (10)
- B64% (29)
- C9% (4)
- D4% (2)
Explanation
On the 9800 WLC, control plane encryption is always enabled, which means that you need to have secure mobility enabled on the AireOS side. However, data link encryption is optional. If you enable it on the 9800 side, enable it on AireOS with: config mobility group member data-dtls controllers/213913-building-mobility-tunnels-on-catalyst-98.html
Topics
Community Discussion
No community discussion yet for this question.