A network administrator configures a WPA2-Enterprise wireless network on a Cisco Wireless LAN Controller (WLC) GUI. On the WLANs > Edit page, the administrator sets the Interface/Interface Group on the General tab to a default VLAN dynamic interface, configures RADIUS authentication under the Security > AAA Servers tab, and confirms 802.1X Key Management under the Security > Layer 2 tab. During testing, wireless clients successfully authenticate against the external RADIUS server, but all clients are assigned to the default dynamic interface specified on the General tab rather than the individual per-user VLAN IDs returned in the RADIUS server IETF attributes (Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID). Which GUI configuration change on the WLC is required to enforce the dynamic VLAN assignments supplied by the RADIUS server?
- Navigate to the Advanced tab of the WLAN edit page and enable the Allow AAA Override option.Answer
- BNavigate to the Security > Layer 3 tab and enable RADIUS Web Authentication.
- CNavigate to the General tab and set the Radio Policy option to FlexConnect Local Switching.
- DNavigate to the Security > Layer 2 tab and select Native VLAN Tagging under WPA2 Parameters.