How to design EWC on Catalyst 9120 for branch campus with HQ 9800 backup?

Design high availability for controllers Determine logical infrastructure requirements such as WLC/AP licensing requirements based on the type of wireless architecture Apply design requirements for these types of wireless networks
Answer Correct answer: D — One C9120 AP per campus becomes EWC, guest uses local web auth, employee 802.1x uses HQ ISE, and HQ 9800 is N+1 backup.

A community bank has three campus locations and one HQ with the data center operations. Each campus location has four Cisco Catalyst 9120 APs. The data center has a Catalyst 9800 WLC with eight Catalyst 9120 APs. Poor WAN uplinks cause impacted branch AP and wireless client connectivity back to HQ, and each campus location is now planned to have its own EWC controller based on C9120 AP to keep traffic local. This new design must accommodate these requirements: • Guest WLAN will be routed locally. • Employee WLAN must be authenticated 802.1x PEAP via HQ data center ISE but can pass traffic locally once authenticated. • HQ WLC will be the primary backup WLC for each WLC. Which design approach should the consulting engineer take?

  1. Two C9120 campus APs must be converted to EWC mode, one for the active controller and the other for standby with HQ WLC set as N+1 backup. The campus guest WLAN will use the guest anchor to HQ WLC for guest VLAN access, and employee WLAN will need the HQ AAA server to be added to EWC and then use that to perform the 802.1x authentication.
  2. One C9120 campus AP must be converted to EWC mode, and the preferred controller is set to that AP with HQ WLC should be paired as mobility peer and configured as N+1 backup. The campus guest WLAN will use local web auth on guest VLAN. The campus employee WLAN will need the guest anchor back to the HQ employee WLAN.
  3. Two C9120 campus APs must be converted to EWC mode, one for the active controller and the other for standby set as N+1 backup. The campus guest WLAN will use local web auth on guest VLAN, and employee WLAN will need the HQ AAA server added to EWC.
  4. One C9120 AP in each campus must be converted to EWC mode, and the preferred controller is set to that AP with HQ WLC set as N+1 backup. The campus guest WLAN will use local web auth on guest VLAN, and employee WLAN will need the HQ AAA server to be added to EWC. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

You must recognize that a single C9120 AP in EWC mode can serve as the campus controller while the HQ 9800 provides N+1 backup, and that adding the HQ ISE as a RADIUS server enables local 802.1x authentication without anchoring employee traffic.

This scenario tests Cisco Catalyst 9120 Embedded Wireless Controller (EWC) design for branch campuses where local guest traffic and 802.1x employee authentication via HQ ISE must be balanced with HQ Catalyst 9800 WLC N+1 backup. The correct approach uses one EWC AP per campus, local web auth for guest, HQ AAA server for employee authentication, and the HQ 9800 as N+1 backup (D).

Many candidates choose C, converting two APs to EWC for active/standby, but the HQ WLC already provides the required backup and the scenario only calls for one EWC controller per campus; guest traffic must remain local, not anchored to HQ.

Community Discussion (3 comments)

55f2ace 👍 1 Selected: D
instead of deploying a standalone controller at the branch site, in ME or EWC mode, one of the APs takes on the role of controller for the other APs at the same location.
Farhad123 👍 1 Selected: D
D is the right one, we just need one AP from each to act as EWLC and use main controller to be HA also HQ user should be added to
Jonycici 👍 1 Selected: D
D is correct.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

D is correct because the requirement is for each campus to have its own EWC controller based on a C9120 AP, with the HQ Catalyst 9800 WLC as the primary backup (N+1). One C9120 AP per campus is converted to EWC mode and set as the preferred controller for the other three campus APs. The HQ 9800 is configured as the N+1 backup, which satisfies the high-availability requirement without needing a second local standby AP. For guest, local web authentication on the guest VLAN keeps guest traffic local, matching the requirement that guest WLAN be routed locally. For employees, the HQ data center ISE is added as an AAA/RADIUS server to the EWC, so 802.1x PEAP authentication occurs against ISE while client data traffic remains local after authentication.

Why the Other Options Are Wrong

Option A is wrong because it anchors the campus guest WLAN to the HQ WLC for guest VLAN access, which contradicts the requirement to route guest traffic locally. It also converts two campus APs to EWC mode unnecessarily, since the HQ WLC serves as the N+1 backup instead of a local standby. Option B is wrong because it uses a guest anchor back to the HQ employee WLAN for the employee WLAN, which removes local traffic forwarding and misapplies the guest anchor concept to employee traffic. Option C is wrong because although it correctly uses local web auth and adds the HQ AAA server, it deploys two EWC APs as active/standby, which is redundant given the HQ WLC N+1 backup requirement and the small four-AP campus design.

Community Comment Notes

The community consensus strongly favors D. One commenter explained that "one of the APs takes on the role of controller" for the other APs at the same location, confirming that a single EWC AP per campus is sufficient. Another commenter, Farhad123, stated: "we just need one AP from each to act as EWLC" and noted the main controller should be HA and HQ user added. Jonycici also confirmed, "D is correct." These comments align with the design choice of one EWC AP per campus, local guest web auth, HQ ISE for employee authentication, and HQ WLC as N+1 backup.

Official Reference

Exam Strategy

Focus on the keyword 'local' — any design that anchors guest or employee traffic back to HQ is wrong because it contradicts the requirement to keep traffic local. Also remember that EWC on a single C9120 AP can serve as the campus controller, and an external 9800 WLC can be configured as N+1 backup, so you don't need a standby EWC AP.

Frequently Asked Questions

Why can a single C9120 AP serve as the EWC controller instead of two for active/standby?

The HQ Catalyst 9800 WLC is configured as the N+1 backup, so the campus does not need a local standby EWC AP; one EWC AP per campus meets the design requirements.

Why must the employee WLAN add the HQ ISE as an AAA server in EWC?

Because the employee WLAN uses 802.1x PEAP authentication via HQ ISE, the EWC must be able to reach that RADIUS server, but client traffic remains local after authentication.

Related Analysis

← Back to 300-425 Study Guide