QuestionQ55

Wireless Network Implementation

A network engineer needs to isolate every guest user connected to a WLAN on a Cisco 9800 WLC so that guests cannot communicate with one another but can access the internet. The WLAN must meet these requirements:

  • SSID named VisitorAccess assigned to VLAN 30
  • Guests prevented from sharing files with other guests
  • Scalability across multiple access points in the building

Which action must the network engineer take to meet these requirements?

  • A Enable P2P blocking in the policy profile and map the WLAN to a dedicated guest VLAN.
  • B Set up local authentication and map the WLAN to a dedicated guest VLAN.
  • C Set up a FlexConnect group and use local switching for the guest WLAN internet access.
  • D Enable multicast mode and associate a RADIUS server with the guest WLAN.
Explanation

Peer-to-peer (P2P) blocking can drop direct traffic between clients associated with the same WLAN, providing guest-to-guest isolation while allowing traffic to the upstream network for internet access. Mapping the guest SSID to a dedicated VLAN provides the required VLAN 30 segmentation and a shared WLAN policy that can be deployed across multiple access points.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!