Soru

Zorluk: Çok zorAP and WLC Management Access Connections

An enterprise network administrator deploys a Cisco Wireless LAN Controller (WLC). The Management Interface is assigned to VLAN 10 with IP address 10.10.10.10/2410.10.10.10/24, and the Service Port is configured on an isolated network with IP address 192.168.1.50/24192.168.1.50/24 for out-of-band management. Engineers in the Network Operations Center (NOC) residing on subnet 172.16.100.0/24172.16.100.0/24 report that they can successfully ping and manage the WLC via HTTPS using the Service Port IP address (192.168.1.50192.168.1.50). However, lightweight Access Points (APs) located on subnet 10.10.20.0/2410.10.20.0/24 consistently fail to complete CAPWAP discovery and join procedures with the Management Interface (10.10.10.1010.10.10.10). Furthermore, NOC engineers cannot establish HTTPS or SSH sessions to 10.10.10.1010.10.10.10, whereas administrative hosts directly connected to VLAN 10 can access 10.10.10.1010.10.10.10 without issue. Which of the following root causes accounts for both the AP CAPWAP join failure and the remote NOC management access timeout to the Management Interface?

  1. The WLC Management Interface lacks a valid default gateway configuration, preventing routed return traffic to remote subnets while allowing local Layer 2 communications.Cevap
  2. B
    The switchport connecting to the WLC Service Port has an 802.1Q native VLAN mismatch with VLAN 10, causing dropped management frames across all WLC logical interfaces.
  3. C
    The Access Points are operating in FlexConnect mode rather than Local mode, which disables CAPWAP control plane discovery to the WLC Management Interface.
  4. D
    CDP TLV negotiation failed between the switch and the WLC Virtual Interface, causing the WLC to shut down Layer 3 routing capabilities across all logical interfaces.

Cevap

The WLC Management Interface lacks a valid default gateway configuration, preventing routed return traffic to remote subnets while allowing local Layer 2 communications.
The correct answer identifies that a missing or invalid default gateway on the WLC Management Interface prevents the WLC from routing return IP packets to subnets outside its local subnet (10.10.10.0/24). Local VLAN 10 devices can communicate using direct Layer 2 switching, and the Service Port functions because it operates on a separate out-of-band routing stack. However, both remote AP CAPWAP join responses and remote NOC management attempts fail because the WLC cannot route return packets to subnets 10.10.20.0/24 or 172.16.100.0/24.

Adım Adım Çözüm

1
Analyze the Service Port management behavior
The Service Port uses a separate, isolated out-of-band routing context with its own static routes and gateway, allowing NOC access to 192.168.1.50 independently of the data plane/Management Interface routing table.
Cisco WLC architecture isolates out-of-band Service Port traffic from the in-band Management and Dynamic interfaces.
2
Compare local vs remote reachability to the Management Interface IP (10.10.10.10)
Local hosts on VLAN 10 (10.10.10.0/24) communicate with the WLC via direct Layer 2 ARP and switching, succeeding without routing. Remote hosts (NOC at 172.16.100.0/24 and APs at 10.10.20.0/24) require Layer 3 routing.
When a remote client sends a packet to the Management Interface, the WLC receives the ingress packet but must consult the Management Interface routing table to send return packets back to the client's gateway.
3
Identify the common failure point for off-subnet APs and off-subnet NOC hosts
Without a valid default gateway configured on the WLC Management Interface, return traffic for CAPWAP join responses (to 10.10.20.0/24) and HTTPS/SSH responses (to 172.16.100.0/24) is dropped by the WLC kernel.
Missing default gateway breaks bidirectional Layer 3 IP connectivity for all remote subnets attempting to communicate with the Management Interface.

Anahtar Kavram

WLC Management Interface Gateway and Routing Isolation
Tahmini Süre:3m 0s
Bu soruyu puanla