nerdexam
Cisco

300-430 · Question #252

Refer to the exhibit. An administrator configures CPU ACLs on the AireOS WLC to implement security. After configuration, administrative users cannot access the user interface. Where must HTTP and…

The correct answer is C. on the management interface. AireOS WLC CPU ACLs filter all traffic destined for the controller CPU, and HTTP/HTTPS administrative traffic must be explicitly permitted on the management interface ACL or administrators will be locked out.

Device Hardening

Question

Refer to the exhibit. An administrator configures CPU ACLs on the AireOS WLC to implement security. After configuration, administrative users cannot access the user interface. Where must HTTP and HTTPS traffic be allowed on the ACLs, based on the configuration?

Exhibit

300-430 question #252 exhibit

Options

  • Aon the dynamic interface
  • Bon the service port of management traffic
  • Con the management interface
  • Don the virtual interface

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    82% (18)
  • D
    9% (2)

Why each option

AireOS WLC CPU ACLs filter all traffic destined for the controller CPU, and HTTP/HTTPS administrative traffic must be explicitly permitted on the management interface ACL or administrators will be locked out.

Aon the dynamic interface

Dynamic interfaces carry client data traffic between the WLC and the distribution layer and are not used for WLC administrative GUI access.

Bon the service port of management traffic

The service port is a dedicated out-of-band management interface with its own separate handling and does not govern in-band HTTP/HTTPS administrative access.

Con the management interfaceCorrect

The management interface on AireOS WLC is the primary interface for all in-band management traffic, including HTTP and HTTPS GUI access. CPU ACLs are applied per interface and evaluated for traffic destined to the WLC CPU - if HTTP and HTTPS are not explicitly allowed in the CPU ACL applied to the management interface, the controller drops that traffic before it reaches the web server process, preventing administrative access.

Don the virtual interface

The virtual interface is used exclusively for client-facing web authentication redirect pages, not for controller administrative access.

Concept tested: AireOS WLC CPU ACL management interface HTTP/HTTPS access

Source: https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/113084-wlc-cpu-acl.html

Topics

#CPU ACL#AireOS WLC#management interface#HTTP/HTTPS access

Community Discussion

No community discussion yet for this question.

Full 300-430 Practice