Question

Difficulty: HardWireless LAN Client Connectivity Configuration via WLC GUI

A network administrator is creating a new WLAN on a Cisco Wireless LAN Controller (WLC) via the web GUI to support corporate users. The WLAN must map client traffic to the dynamic interface associated with VLAN 20 and authenticate clients using WPA2-Enterprise (802.1X) against a central external RADIUS server that has already been globally configured on the controller. Which two configuration actions must the administrator perform within the WLAN configuration tabs in the WLC GUI to successfully complete this setup? (Select two.)

  1. Under the General tab, select the dynamic interface mapped to VLAN 20 from the Interface/Interface Group dropdown menu and check the Enabled box for Status.Answer
  2. Under the Security > AAA Servers tab, select the pre-configured RADIUS server from the Server 1 dropdown list in the Authentication Servers section.Answer
  3. C
    Under the Security > Layer 3 tab, select 802.1X from the Layer 3 Security drop-down menu and enter the RADIUS shared secret key.
  4. D
    Under the Advanced tab, change the AP Operating Mode to FlexConnect and check the Local EAP Authentication checkbox.

Answer

The administrator must map the WLAN to the dynamic interface for VLAN 20 and enable the WLAN status under the General tab, as well as select the pre-configured RADIUS server under the Security > AAA Servers tab.
To complete WLAN client connectivity configuration for WPA2-Enterprise with VLAN tagging: 1) Under the General tab, the WLAN must be associated with the appropriate dynamic interface (VLAN 20) and the Status box must be checked to enable SSID broadcasting and association. 2) Under the Security > AAA Servers tab, the specific external RADIUS server must be bound to the WLAN so authentication traffic is forwarded correctly.

Step-by-Step Solution

1
Navigate to the WLANs tab in the WLC GUI and edit the target WLAN.
Access the multi-tab configuration interface for the specific WLAN.
WLAN settings are organized into General, Security, AAA Servers, QoS, and Advanced tabs.
2
Select the dynamic interface for VLAN 20 and check the Enabled checkbox under the General tab.
Traffic from clients associating to this WLAN is mapped to VLAN 20, and the WLAN is brought administratively online.
Without enabling Status, the WLAN remains inactive; without binding the dynamic interface, client traffic cannot reach VLAN 20.
3
Navigate to Security > AAA Servers tab and select the globally configured RADIUS server under Authentication Servers.
The WLAN is instructed to send 802.1X authentication requests to the designated external RADIUS server.
Global RADIUS definitions must be explicitly assigned to individual WLANs under the WLAN AAA Servers tab for 802.1X Enterprise security.

Key Concept

WLC GUI WLAN Client Connectivity and Security Configuration Parameters
Estimated Time:2m 0s
Rate this question