Volume 2 - Chapter 4: Building a Wireless LAN Flashcards
Describe the purpose of the service port on a Cisco WLC.
The service port allows for Out-Of-Band management via SSH or HTTPS.
Also referred to as a data management interface.
What port on a Cisco WLC is used to enable HA operations?
The redudancy port.
The data Ethernet port on a Cisco WLC is referred to as?
The distribution system ports.
What type of EtherChannel configuration is supported for the WLC’s distribution (Ethernet) ports?
A static LAG (Link Aggregation Group).
What type of interface is used to map a WLAN to a VLAN on the wireless controller?
The dynamic interface.
What layer do dynamic interfaces operate at on an IOS-XE wireless controller?
Layer 2
What layer do dynamic interfaces operate at on an AireOS wireless controller?
Layer 3
What configuration(s) are required on a dynamic interface on an AireOS controller?
IP Address, Subnet Mask, Default Gateway and a DHCP Server
Describe the purpose of the Wireless Management Interface (WMI) on a Cisco WLC.
Both IOS-XE and AireOS use WMIs for the same purpose:
- Terminating CAPWAP tunnels
- RADIUS authentications
- WLC to WLC communications
- SSH, NTP, and SNMP
What interface on a WLC uses a unique non-routable address and is used for specific client facing operations?
For example, relaying DHCP requests to a DHCP server.
The virtual interface
What is the maximum amount of WLANs that can be configured on a Cisco WLC?
512
What is the maximum amount of WLANs that can be active at one time on a Cisco WLC?
16
Each WLAN is advertised via their own unique ____.
Beacon.
How many active WLANs are recommened in a single area?
5 or fewer, but 3 maximum is best.
What are the 3 categories (tags) of AP operation on an IOS-XE controller?
Policy, Site, and RF.
Where is the category that the following parameters fall under?:
- SSID and band settings
- Layer 2 & 3 security
- AAA
Under Policy > WLAN Profile
Where is the category that the following parameters fall under?:
- VLANs
- Multicast
- ACLs and URL Filters
- QoS Policies
Under Policy > Policy Profile
Where is the category that the following parameters fall under?:
- CAPWAP Timers
- Rogue Detection
- AP Fallback
Under Site > AP Profile.
Where is the category that the following parameters fall under?:
- Native VLANs
- Local Authenitcation
- DNS Security
Under Site > Flex Profile.
Describe the purpose of the Policy category on an IOS-XE controller.
Policies define the WLANs and their security policies
Describe the purpose of the Site category on an IOS-XE controller.
Settings for the AP controller and CAPWAP/FlexConnect behavior on a per-site basis.
Describe the purpose of the RF category on an IOS-XE controller.
Settings for wireless bands and transmission.
Where are new VLANs created on a IOS-XE controller?
Under Configuration > Wireless Setup > WLANs
What layer 2 security options are available for an SSID?
5 Options:
- WPA + WPA2
- WPA2 + WPA3
- WPA3
- Static WEP
- None
A technician enables layer 2 security using the WPA + WPA2 option, but wants to only enable WPA2 and disable WPA.
How can they do this?
After selecting the WPA + WPA2 option, they can disable the WPA Policy by unchecking the box
What is the default encryption for WPA2?
AES (CCMP128)
What option is enabled by default and allows wireless client roaming and reauthentication as clients move?
Fast Transition (FT).
What is the default amount of max connections per WLAN when a WLAN is created?
0 (unlimited)
What is the default amount of max connections per AP per WLAN when a WLAN is created?
0 (unlimited)
What is the default amount of max connections per AP raido per WLAN when a WLAN is created?
200
What advanced option can be enabled to allow the controller to distribute clients across neighboring APs?
Load Balancing.
True or False:
The 802.11ax option is enabled by default.
True.
Where can the setting for the VLAN mapping to the WLAN configured?
Add Policy Profile > Access Policies > VLAN.
Where can the setting for the WLAN sesstion and idle timeouts be configured?
Add Policy Profile > Advanced > WLAN Timeout
What is the default session timeout for a WLAN?
1800 seconds (30 minutes).