300-430 Question 27
Single answerA network engineer is configuring a Cisco WLAN deployment with a mix of VLAN-based central switching and FlexConnect local switching to optimize traffic flow. The engineer must apply specific access control policies on the local APs in a branch office to restrict access to certain devices. Which feature should the engineer configure to enforce these policies effectively?
- A
FlexConnect ACLs
- B
VLAN ACLs (VACLs)
- C
Centralized ACLs on the WLC
- D
Dynamic Access Control Lists
Show answer and explanation
Correct answer: A
Explanation
FlexConnect ACLs enable administrators to enforce Layer 2 and Layer 3 access control policies directly on FlexConnect APs when operating in local switching mode. This is essential for branch deployments where traffic does not traverse the centralized controller, allowing for local policy enforcement without relying on WLC processing.
- A. Correct.
FlexConnect ACLs are designed to enable access control policies on FlexConnect APs when operating in local switching mode. This is the correct choice for applying access restrictions directly at branch APs.
- B. Incorrect.
VLAN ACLs (VACLs) are applied at the switch level and are not specific to the AP or WLAN deployment. They are not suitable for enforcing policies on FlexConnect APs.
- C. Incorrect.
Centralized ACLs on the WLC are applied when WLAN traffic is centrally switched through the controller. This is not applicable to FlexConnect APs operating in local switching mode.
- D. Incorrect.
Dynamic Access Control Lists are not a feature designed for FlexConnect AP configurations. This option is irrelevant to the scenario.