nerdexam
Cisco

300-430 · Question #284

An engineer must deploy FlexConnect APs to a branch office. If the connection to the WLC fails and 802.1X authentication is available, users must stay connected to the AP. Which FlexConnect state…

The correct answer is B. Authentication Local/Switch Local. FlexConnect APs in a branch must survive WLC connectivity loss while still performing 802.1X authentication, requiring both authentication and switching to be handled locally at the AP.

FlexConnect

Question

An engineer must deploy FlexConnect APs to a branch office. If the connection to the WLC fails and 802.1X authentication is available, users must stay connected to the AP. Which FlexConnect state should be implemented?

Options

  • AAuthentication Central/Switch Central
  • BAuthentication Local/Switch Local
  • CAuthentication Central/Switch Local
  • DAuthentication Local/Switch Central

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    78% (31)
  • C
    8% (3)
  • D
    3% (1)

Why each option

FlexConnect APs in a branch must survive WLC connectivity loss while still performing 802.1X authentication, requiring both authentication and switching to be handled locally at the AP.

AAuthentication Central/Switch Central

Authentication Central/Switch Central tunnels both authentication and data to the WLC, so any WLC connectivity failure immediately drops all clients with no local fallback.

BAuthentication Local/Switch LocalCorrect

Authentication Local/Switch Local means the FlexConnect AP performs 802.1X authentication against a locally stored credential cache and switches client traffic locally without tunneling to the WLC. When the WLC connection is lost and the AP enters standalone mode, this configuration allows clients to re-authenticate and maintain connectivity because neither authentication nor data switching depends on the WLC being reachable.

CAuthentication Central/Switch Local

Authentication Central/Switch Local locally switches data but still depends on the WLC for 802.1X authentication, meaning clients cannot authenticate when the WLC link fails.

DAuthentication Local/Switch Central

Authentication Local/Switch Central allows local authentication but tunnels client data to the WLC, so traffic cannot flow if the WLC connection is unavailable, making this unsuitable for branch resiliency.

Concept tested: FlexConnect AP standalone mode authentication and switching

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/flexconnect.html

Topics

#FlexConnect#802.1X authentication#standalone mode#local switching

Community Discussion

No community discussion yet for this question.

Full 300-430 Practice