300-430 Question 323
Select 3An enterprise network administrator is configuring a Cisco WLC to restrict specific control plane traffic to enhance security. Which of the following steps are required to implement control plane ACLs on the controller?
- A
Create an ACL in the Cisco WLC and define the permit or deny rules for specific control plane traffic.
- B
Apply the ACL to the management interface of the Cisco WLC to filter control plane traffic.
- C
Bind the ACL to a WLAN profile to control user data traffic.
- D
Enable CPU ACL under the Advanced tab of the Cisco WLC GUI settings.
- E
Ensure the ACL is applied to the AP Manager interface to filter traffic to access points.
Show answer and explanation
Correct answers: A, B, D
Explanation
Control plane ACLs on a Cisco WLC are used to filter traffic directed to the WLC’s CPU, such as management traffic, to enhance security. To implement control plane ACLs, administrators must first create the ACL, apply it to the management interface, and enable the CPU ACL feature in the WLC GUI. This ensures that only authorized traffic can reach the controller's control plane.
- A. Correct.
Correct. Creating an ACL in the Cisco WLC and defining the permit or deny rules is the first step in configuring control plane ACLs.
- B. Correct.
Correct. Control plane ACLs are applied to the management interface to filter traffic directed to the CPU or controller.
- C. Incorrect.
Incorrect. Binding an ACL to a WLAN profile is used for data plane traffic, not for control plane ACLs.
- D. Correct.
Correct. Enabling CPU ACL under the Advanced tab activates the control plane traffic filtering defined by the ACL.
- E. Incorrect.
Incorrect. The AP Manager interface is used for communication between the WLC and APs, but applying an ACL here does not control the WLC’s control plane traffic.