300-425 · Question #208
Refer to the exhibit. An engineer is about to establish a mobility peer connection between a Cisco Catalyst 9800-CL version 16.10.1 e and Cisco AireOS 5520 version 8.8.120.0. The data path between…
The correct answer is D. The certificate hash key is missing from the AireOS 5520 WLC mobility configuration, which. Inter-release Cisco mobility between an IOS-XE 9800-CL and an AireOS 5520 requires both controllers to have each other's certificate hash configured; a missing hash on the AireOS side prevents the DTLS control path from establishing.
Question
Refer to the exhibit. An engineer is about to establish a mobility peer connection between a Cisco Catalyst 9800-CL version 16.10.1 e and Cisco AireOS 5520 version 8.8.120.0. The data path between the 9800-CL and AireOS 5520 is up, but its control path is down. Based on the configuration, what is the root of the issue?
Options
- AThe data-link-encryption configuration is missing from the 9800-CL configuration.
- BCAPS is used to key in the MAC address in the IOS_XE configuration, which causes the control
- CEncrypted mobility is being used in the 5520 configuration, which causes the control path to be
- DThe certificate hash key is missing from the AireOS 5520 WLC mobility configuration, which
How the community answered
(31 responses)- A16% (5)
- B29% (9)
- C6% (2)
- D48% (15)
Why each option
Inter-release Cisco mobility between an IOS-XE 9800-CL and an AireOS 5520 requires both controllers to have each other's certificate hash configured; a missing hash on the AireOS side prevents the DTLS control path from establishing.
The data-link-encryption setting governs DTLS encryption on the mobility data path; since the data path is confirmed operational, this configuration is present and working correctly.
MAC address capitalization in the IOS-XE configuration may cause peer lookup issues, but this would typically prevent both paths from forming, not selectively cause the control path to fail while the data path remains up.
An encrypted mobility mismatch between the two controllers would prevent both the control and data paths from establishing; because the data path is confirmed up, encrypted mobility settings are not the cause of the control path failure.
When pairing an IOS-XE 9800 series controller with a legacy AireOS controller for inter-release mobility, both sides must exchange and configure each other's certificate hash to authenticate the DTLS control tunnel. If the AireOS 5520 is missing the 9800-CL certificate hash in its mobility peer configuration, it cannot validate the peer identity and the control path will remain down. The data path uses a separate UDP tunnel that does not require this certificate validation, which is why it can be up while the control path is down.
Concept tested: Cisco 9800-CL to AireOS inter-release mobility certificate hash
Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/16-10/config-guide/b_wl_16_10_cg/mobility.html
Topics
Community Discussion
No community discussion yet for this question.