Catalyst 9800 and AireOS 5520 Mobility Data Path Down
Refer to the exhibit. An engineer is about to establish a mobility peer connection between a Cisco Catalyst 9800-CL version 16.10.1e and Cisco AireOS 5520 version 8.8.120.0. The data path between the 9800-CL and AireOS 5520 is down, but its control path is up. Based on the configuration, what is the cause of the issue? - 
Community Votes
50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests mobility data path troubleshooting between 9800 and AireOS; the trap is confusing control path status with a data DTLS encryption mismatch.
This 300-425 question examines why the data path fails between a Catalyst 9800-CL and an AireOS 5520 while the control path remains up. The correct answer is C: data DTLS is disabled on the AireOS 5520, causing a mismatch in mobility data path encryption.
Many candidates choose D, assuming the 9800-CL is missing data-link-encryption, but the exhibit shows data-dtls explicitly disabled on the AireOS 5520.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The mobility control path between the 9800-CL and the AireOS 5520 is up, meaning UDP 16666 is reachable and the mobility group member configuration is valid. The exhibit shows the AireOS 5520 command config mobility group member data-dtls 00:1e:14:08:fb:ff disable, which turns off DTLS encryption for the data path (UDP 16667) toward the 9800-CL peer. Because the 9800-CL uses data DTLS by default, the mismatch prevents the data path from establishing even though control messages still flow. Enabling data DTLS on the 5520 (or disabling it on the 9800-CL) would bring the data path up. Therefore option C correctly identifies the disabled data-dtls setting on the AireOS side as the cause.
Why the Other Options Are Wrong
Option A is wrong because an incorrect certificate hash would also break data path establishment, but the exhibit shows an explicit "disable" command rather than a wrong hash value; the hash is not the issue when DTLS is turned off entirely. Option B is wrong because encrypted mobility is a control path encryption feature, and the control path is already up, so it cannot explain the data path failure. Option D is wrong because the 9800-CL does not need an additional data-link-encryption configuration when the AireOS side has data DTLS disabled; the mismatch is caused by the AireOS 5520 disabling data DTLS, not by a missing line on the 9800-CL. In fact, the 9800-CL default is to have data DTLS enabled, so the AireOS 5520's disabled state is the outlier.
Community Comment Notes
Farhad123 directly quoted the AireOS command "config mobility group member data-dtls 00:1e:14:08:fb:ff disable" and voted for C, which aligns with the exhibit's explicit DTLS disable. Reinier_veen referenced Question 87 to argue for D, but that scenario involves a different configuration where the 9800-CL is missing data-link-encryption; here the exhibit clearly shows the AireOS 5520 disabling data-dtls. The community is split 50/50, but the specific command in the exhibit makes C the stronger answer. No other commenter provided a contradictory configuration detail.
Exam Strategy
Focus on the data path vs control path distinction: control path uses UDP 16666 and confirms peer reachability, while data path uses UDP 16667 and depends on matching data DTLS settings. Check the AireOS data-dtls disable command in the exhibit before assuming a 9800 missing config.
Frequently Asked Questions
Why is option D wrong if the 9800-CL lacks data-link-encryption?
The exhibit explicitly shows data-dtls disabled on the AireOS 5520; the 9800-CL default data DTLS state is enabled, so the mismatch originates on the AireOS side.
How do I fix the data path between 9800-CL and AireOS 5520?
Enable data DTLS on the AireOS 5520 with config mobility group member data-dtls <mac> <hash>, or disable data DTLS on the 9800-CL to match.