Configuring NAC in-band with Cisco WLC | CCIE Wireless Written Exam

Configuring NAC in-band with Cisco WLC

Question

When configuring NAC in-band to work with a Cisco WLC, which statement is true, from a WLC perspective?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

D.

NAC (Network Access Control) is a security solution that helps to ensure that only authorized devices can connect to a network. When configuring NAC in-band to work with a Cisco Wireless LAN Controller (WLC), there are several considerations to keep in mind.

A. NAC always needs to be enabled in the WLAN configuration.

This statement is true. When configuring NAC in-band with a Cisco WLC, the NAC feature needs to be enabled in the WLAN configuration. This ensures that NAC policies are enforced for all devices connecting to the WLAN.

B. The Clean Access Server always needs to be configured as a RADIUS accounting server on the Cisco WLC.

This statement is false. While the Clean Access Server (CAS) is a component of Cisco NAC, it is not always necessary to configure it as a RADIUS accounting server on the WLC. In fact, there are different deployment models for Cisco NAC that may involve different server roles and configurations.

C. The Clean Access Manager always needs to be configured in the SNMP trap receiver.

This statement is false. The Clean Access Manager (CAM) is another component of Cisco NAC, but it is not always necessary to configure it in the SNMP trap receiver. The SNMP trap receiver is used to receive SNMP traps from the WLC and other network devices, but the CAM may not always be sending traps to the WLC.

D. Only the quarantine VLAN ID needs to be configured as the WLAN interface.

This statement is false. When configuring NAC in-band with a Cisco WLC, there are several WLAN interface parameters that need to be configured, including the VLAN ID for the quarantine VLAN, the VLAN ID for the authentication VLAN, the NAC state RADIUS server, and others. Configuring only the quarantine VLAN ID is not sufficient for proper NAC operation.

In summary, when configuring NAC in-band with a Cisco WLC, it is important to enable the NAC feature in the WLAN configuration, and to configure all necessary WLAN interface parameters, such as VLAN IDs, RADIUS servers, and others. The specific configurations may vary depending on the deployment model and the specific requirements of the network.