nerdexam
Cisco

300-425 · Question #208

Refer to the exhibit. An engineer is about to establish a mobility peer connection between a Cisco Catalyst 9800-CL version 16.10.1 e and Cisco AireOS 5520 version 8.8.120.0. The data path between…

The correct answer is D. The certificate hash key is missing from the AireOS 5520 WLC mobility configuration, which. Inter-release Cisco mobility between an IOS-XE 9800-CL and an AireOS 5520 requires both controllers to have each other's certificate hash configured; a missing hash on the AireOS side prevents the DTLS control path from establishing.

Monitoring and Troubleshooting

Question

Refer to the exhibit. An engineer is about to establish a mobility peer connection between a Cisco Catalyst 9800-CL version 16.10.1 e and Cisco AireOS 5520 version 8.8.120.0. The data path between the 9800-CL and AireOS 5520 is up, but its control path is down. Based on the configuration, what is the root of the issue?

Options

  • AThe data-link-encryption configuration is missing from the 9800-CL configuration.
  • BCAPS is used to key in the MAC address in the IOS_XE configuration, which causes the control
  • CEncrypted mobility is being used in the 5520 configuration, which causes the control path to be
  • DThe certificate hash key is missing from the AireOS 5520 WLC mobility configuration, which

How the community answered

(31 responses)
  • A
    16% (5)
  • B
    29% (9)
  • C
    6% (2)
  • D
    48% (15)

Why each option

Inter-release Cisco mobility between an IOS-XE 9800-CL and an AireOS 5520 requires both controllers to have each other's certificate hash configured; a missing hash on the AireOS side prevents the DTLS control path from establishing.

AThe data-link-encryption configuration is missing from the 9800-CL configuration.

The data-link-encryption setting governs DTLS encryption on the mobility data path; since the data path is confirmed operational, this configuration is present and working correctly.

BCAPS is used to key in the MAC address in the IOS_XE configuration, which causes the control

MAC address capitalization in the IOS-XE configuration may cause peer lookup issues, but this would typically prevent both paths from forming, not selectively cause the control path to fail while the data path remains up.

CEncrypted mobility is being used in the 5520 configuration, which causes the control path to be

An encrypted mobility mismatch between the two controllers would prevent both the control and data paths from establishing; because the data path is confirmed up, encrypted mobility settings are not the cause of the control path failure.

DThe certificate hash key is missing from the AireOS 5520 WLC mobility configuration, whichCorrect

When pairing an IOS-XE 9800 series controller with a legacy AireOS controller for inter-release mobility, both sides must exchange and configure each other's certificate hash to authenticate the DTLS control tunnel. If the AireOS 5520 is missing the 9800-CL certificate hash in its mobility peer configuration, it cannot validate the peer identity and the control path will remain down. The data path uses a separate UDP tunnel that does not require this certificate validation, which is why it can be up while the control path is down.

Concept tested: Cisco 9800-CL to AireOS inter-release mobility certificate hash

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/16-10/config-guide/b_wl_16_10_cg/mobility.html

Topics

#mobility peer#certificate hash#IOS XE AireOS interop#control path failure

Community Discussion

No community discussion yet for this question.

Full 300-425 Practice