nerdexam
Huawei

H12-311_V3.0 · Question #128

The wireless users of the same user VLAN and the same SSID can access the Internet, but they cannot access each other. What may be the reason for this phenomenon?

The correct answer is D. User isolation is configured on the wireless service-set, preventing mutual access between users. User isolation, when configured on a wireless service-set (SSID profile), operates at Layer 2 and blocks direct communication between wireless clients on the same SSID while leaving upstream traffic to the Internet unaffected - this precisely matches the described symptom…

WLAN Security Technologies

Question

The wireless users of the same user VLAN and the same SSID can access the Internet, but they cannot access each other. What may be the reason for this phenomenon?

Options

  • AACL is configured on the user's gateway device, which prevents mutual access between users
  • BACL is configured on the AC, which prevents mutual access between users
  • CThe port isolation configured on the switch connected to the AP prevents mutual access between
  • DUser isolation is configured on the wireless service-set, preventing mutual access between users

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    10% (5)
  • C
    6% (3)
  • D
    81% (39)

Explanation

User isolation, when configured on a wireless service-set (SSID profile), operates at Layer 2 and blocks direct communication between wireless clients on the same SSID while leaving upstream traffic to the Internet unaffected - this precisely matches the described symptom. Option A is incorrect because an ACL on the gateway would not stop same-subnet clients from communicating at Layer 2 before traffic even reaches the gateway, and it would not produce this exact pattern cleanly. Option B is unlikely because applying inter-user blocking via an ACL on the AC is not a standard mechanism for this behavior, and the scenario points to a wireless-specific feature. Option C fails because all clients on the same AP share a single uplink port to the switch, so port isolation between switch ports has no effect on clients communicating through that shared port - port isolation only separates different ports, not traffic within the same port. Memory tip: user isolation is a wireless-layer feature attached to the service-set itself, so when the problem says "same SSID, same VLAN, Internet works but peers cannot reach each other," the culprit is always the wireless client isolation setting, not ACLs or switch port configuration.

Topics

#user isolation#wireless security#SSID configuration#AP isolation

Community Discussion

No community discussion yet for this question.

Full H12-311_V3.0 Practice