300-425 · Question #219
An engineer created a design where the HQ has a Cisco 5520 Wireless LAN Controller with 2000 APs associated to it. If a controller at one of the remote sites fails, the APs at that site fall back to…
The correct answer is C. Ensure that the critical APs at HQ have a failover priority of "critical", leave the rest of the HQ APs. When Global AP Failover Priority is enabled, APs with 'critical' priority cannot be displaced by lower-priority APs joining during a failover event, protecting key HQ APs while still permitting remote APs to failover.
Question
An engineer created a design where the HQ has a Cisco 5520 Wireless LAN Controller with 2000 APs associated to it. If a controller at one of the remote sites fails, the APs at that site fall back to a central controller. Global AP Failover Priority must be enabled. Which design approach must be taken to prevent the critical APs at HQ from going down and still allow APs to failover to the HQ controller?
Options
- ASet all the APs at HQ to a failover priority of "high" and set the remote site APs to "normal".
- BSet all the APs at HQ to a failover priority of "medium" and set the remote site APs to "high".
- CEnsure that the critical APs at HQ have a failover priority of "critical", leave the rest of the HQ APs
- DCreate an access list on the HQ router that blocks CAPWAP discovery on UDP port 5246 so that
How the community answered
(40 responses)- A15% (6)
- B5% (2)
- C73% (29)
- D8% (3)
Why each option
When Global AP Failover Priority is enabled, APs with 'critical' priority cannot be displaced by lower-priority APs joining during a failover event, protecting key HQ APs while still permitting remote APs to failover.
Setting HQ APs to 'high' instead of 'critical' does not use the topmost protection tier, meaning any future remote APs also configured as 'high' could still displace HQ APs when the controller is at capacity.
Setting HQ APs to 'medium' and remote APs to 'high' is backwards - the remote APs would have higher priority than the HQ APs, causing HQ APs to be bumped off the controller during a remote-site failover event.
Setting the most essential HQ APs to 'critical' failover priority ensures they will never be bumped off the 5520 WLC when remote-site APs attempt to failover to it. The Cisco WLC failover priority hierarchy is Critical, High, Medium, and Low - critical APs are fully protected from displacement even when the controller approaches its AP capacity ceiling. Leaving the remaining HQ APs at a lower priority tier allows incoming remote APs to join without risking the most important local infrastructure.
Blocking CAPWAP discovery via an ACL on UDP port 5246 would prevent remote APs from ever reaching the HQ controller, completely defeating the purpose of the failover design.
Concept tested: Cisco WLC AP failover priority tier configuration
Source: https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213535-understand-and-configure-ap-failover-pri.html
Topics
Community Discussion
No community discussion yet for this question.