300-425 Question 21
Select 3An enterprise has deployed a wireless network for remote branch offices using Cisco FlexConnect. The remote branches require local internet breakout for certain applications, while corporate traffic must be tunneled back to the data center. What configuration ensures split tunneling and fault tolerance in this scenario?
- A
Configure FlexConnect local switching for internet-bound traffic and centrally switched corporate traffic.
- B
Enable FlexConnect local authentication to ensure continued connectivity during WAN link failure.
- C
Configure ACLs on the WLAN to allow local breakout for specific applications.
- D
Use FlexConnect AP groups to separate local and corporate traffic paths.
- E
Enable Client Exclusion Policies to block devices using unsupported applications.
Show answer and explanation
Correct answers: A, B, C
Explanation
In this scenario, split tunneling is achieved by configuring FlexConnect local switching for internet-bound traffic and centrally switching corporate traffic. To ensure fault tolerance, local authentication is enabled so clients can connect even if the WAN link fails. ACLs further refine the split tunneling by allowing specific applications to use local breakout. FlexConnect AP groups and Client Exclusion Policies are not relevant to this configuration.
- A. Correct.
Correct: FlexConnect local switching enables split tunneling by allowing internet-bound traffic to break out locally while tunneling corporate traffic back to the data center.
- B. Correct.
Correct: Local authentication ensures fault tolerance by allowing clients to authenticate locally at the branch even if the WAN link to the data center is down.
- C. Correct.
Correct: ACLs can be used to identify and permit specific applications for local breakout, ensuring the split tunneling functionality works as intended.
- D. Incorrect.
Incorrect: FlexConnect AP groups are used for grouping access points with similar configuration needs but do not directly control traffic paths for split tunneling.
- E. Incorrect.
Incorrect: Client Exclusion Policies are used for blocking misbehaving or unauthorized clients, which is unrelated to split tunneling or fault tolerance.