300-430 · Question #284
An engineer must deploy FlexConnect APs to a branch office. If the connection to the WLC fails and 802.1X authentication is available, users must stay connected to the AP. Which FlexConnect state…
The correct answer is B. Authentication Local/Switch Local. FlexConnect APs in a branch must survive WLC connectivity loss while still performing 802.1X authentication, requiring both authentication and switching to be handled locally at the AP.
Question
An engineer must deploy FlexConnect APs to a branch office. If the connection to the WLC fails and 802.1X authentication is available, users must stay connected to the AP. Which FlexConnect state should be implemented?
Options
- AAuthentication Central/Switch Central
- BAuthentication Local/Switch Local
- CAuthentication Central/Switch Local
- DAuthentication Local/Switch Central
How the community answered
(40 responses)- A13% (5)
- B78% (31)
- C8% (3)
- D3% (1)
Why each option
FlexConnect APs in a branch must survive WLC connectivity loss while still performing 802.1X authentication, requiring both authentication and switching to be handled locally at the AP.
Authentication Central/Switch Central tunnels both authentication and data to the WLC, so any WLC connectivity failure immediately drops all clients with no local fallback.
Authentication Local/Switch Local means the FlexConnect AP performs 802.1X authentication against a locally stored credential cache and switches client traffic locally without tunneling to the WLC. When the WLC connection is lost and the AP enters standalone mode, this configuration allows clients to re-authenticate and maintain connectivity because neither authentication nor data switching depends on the WLC being reachable.
Authentication Central/Switch Local locally switches data but still depends on the WLC for 802.1X authentication, meaning clients cannot authenticate when the WLC link fails.
Authentication Local/Switch Central allows local authentication but tunnels client data to the WLC, so traffic cannot flow if the WLC connection is unavailable, making this unsuitable for branch resiliency.
Concept tested: FlexConnect AP standalone mode authentication and switching
Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/flexconnect.html
Topics
Community Discussion
No community discussion yet for this question.