Restricting a WLAN to DHCP and DNS with a Web Policy

Interpret the wireless LAN GUI configuration for client connectivity, such as WLAN creation, security settings, QoS profiles, and advanced settings
Answer Correct answer: C — On the WLC, a Layer 3 Security Web Policy applies a pre-authentication ACL that restricts clients to DHCP and DNS until they authenticate.

Refer to the exhibit. A network engineer must configure the WLC to allow only DHCP and DNS packets for User1 and User2. Which configuration must be used? - image

  1. Enable Web Authentication for 802.1X standard in the Layer 2 Security configuration
  2. Enable Fallback Policy with MAC filtering under the Layer 3 Security configuration
  3. Enable Web policy and Authentication in the Layer 3 Security configuration. Correct Answer
  4. Enable Web Authentication under the AAA Server configuration on the WLAN.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Pre-authentication ACLs that permit only DHCP/DNS live under Layer 3 Security > Web Policy on the WLC; that is the only option that maps to traffic restriction before full auth.

To let unauthenticated clients reach only DHCP and DNS, the WLC uses a Layer 3 Security Web Policy together with a pre-authentication ACL. This is configured under the WLAN's Layer 3 Security, not under Layer 2 802.1X or AAA server web auth.

Picking 802.1X (A) or AAA web auth (D): those change the auth method, not the permitted traffic. MAC filtering fallback (B) filters by MAC, not by protocol (DHCP/DNS).

Community Discussion (3 comments)

Starlord2535 👍 5 Selected: C
None of the provided options directly address the specific task of allowing only DHCP and DNS packets. However, configuring Layer 3 security with web policy and authentication (Option C) is related to controlling access on the network at Layer 3, which could involve the use of ACLs to restrict traffic types[3]. Yet, this option does not specifically mention the use of ACLs for controlling DHCP and DNS traffic, which is the core requirement. To specifically allow only DHCP and DNS packets, you would typically: 1. Create ACLs that permit traffic on the ports used by DHCP (ports 67 and 68) and DNS (port 53). 2. Apply these ACLs to the user profiles or WLANs that User1 and User2 are associated with, ensuring that only DHCP and DNS traffic is allowed while all other traffic types are denied.
kalitwol 👍 2 Selected: C
its we need layer 3 security
askar430 👍 1 Selected: A
i think its A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

C is correct. A WLC Web Policy configured under Layer 3 Security applies a pre-authentication ACL that can permit only DHCP and DNS traffic before a client fully authenticates, which is exactly the stated requirement.

Why the Other Options Are Wrong

A (Web Authentication for 802.1X) changes the Layer 2 auth method and does not restrict protocols. B (Fallback Policy with MAC filtering) filters by MAC address, not by DHCP/DNS. D (Web Authentication under AAA Server) is an auth placement, not the DHCP/DNS traffic ACL.

Community Comment Notes

The community vote is C (89). One commenter notes none of the options mention ACLs directly, but Layer 3 Web Policy is the configuration that carries the pre-auth ACL controlling DHCP/DNS.

Official Reference

Related Analysis

Practice All 200-301 Questions

Access 220 questions with complete answers and detailed explanations.

View Full 200-301 Practice Test →

← Back to 200-301 Study Guide