nerdexam
Cisco

300-425 · Question #51

Guest anchoring is configured for a newly created SSID for your company. It has been noticed that the mobility tunnels are not up, and that MPING fails from your foreign WLC to the anchor WLC. What…

The correct answer is A. A rule is needed at the firewall to allow UDP port 16666 for communication to work. Cisco WLC mobility control traffic including MPING uses UDP port 16666, so a firewall blocking this port will prevent mobility tunnels from forming between foreign and anchor controllers.

Mobility

Question

Guest anchoring is configured for a newly created SSID for your company. It has been noticed that the mobility tunnels are not up, and that MPING fails from your foreign WLC to the anchor WLC. What is the reason that it is failing?

Options

  • AA rule is needed at the firewall to allow UDP port 16666 for communication to work.
  • BA rule is needed at the firewall to allow UDP port 97 for communication to work.
  • CA rule is needed at the firewall to allow TCP port 97 for communication to work.
  • DA rule is needed at the firewall to allow TCP port 16666 for communication to work.

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    5% (2)
  • C
    2% (1)
  • D
    2% (1)

Why each option

Cisco WLC mobility control traffic including MPING uses UDP port 16666, so a firewall blocking this port will prevent mobility tunnels from forming between foreign and anchor controllers.

AA rule is needed at the firewall to allow UDP port 16666 for communication to work.Correct

Cisco WLC-to-WLC mobility messaging, including MPING (mobility ping) used to verify mobility tunnel reachability, is transmitted over UDP port 16666. If a firewall between the foreign and anchor WLC does not permit UDP 16666, the mobility handshake cannot complete and tunnels will remain down. Opening UDP 16666 bidirectionally between the controllers resolves the MPING failure and allows guest anchoring to function.

BA rule is needed at the firewall to allow UDP port 97 for communication to work.

UDP port 97 is used for EoIP (Ethernet over IP) data tunneling in mobility architectures, not for MPING mobility control traffic.

CA rule is needed at the firewall to allow TCP port 97 for communication to work.

Cisco WLC mobility control uses UDP, not TCP, so TCP port 97 is not involved in any WLC mobility tunnel function.

DA rule is needed at the firewall to allow TCP port 16666 for communication to work.

TCP port 16666 is incorrect because WLC mobility control traffic uses UDP, not TCP, for its communication channel.

Concept tested: WLC guest anchoring mobility tunnel firewall port requirements

Source: https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/107609-cuwn-port-reference.html

Topics

#guest anchoring#MPING#mobility tunnel#UDP 16666

Community Discussion

No community discussion yet for this question.

Full 300-425 Practice