Catalyst 9800 and AireOS 5520 Mobility Data Path Down

Validate mobility tunneling for data and control path
Answer Correct answer: C — Data DTLS is disabled on the AireOS 5520, causing the mobility data path to go down while the control path remains up.

Refer to the exhibit. An engineer is about to establish a mobility peer connection between a Cisco Catalyst 9800-CL version 16.10.1e and Cisco AireOS 5520 version 8.8.120.0. The data path between the 9800-CL and AireOS 5520 is down, but its control path is up. Based on the configuration, what is the cause of the issue? - image

  1. The certificate hash key is incorrect, which causes the data path to be down.
  2. Encrypted mobility is being used in the 5520 configuration, which causes the data path to be down.
  3. The data-dtls is disabled on the AireOS 5520 WLC, which causes the data path to be down. Correct Answer
  4. The data-link-encryption configuration is missing from the 9800-CL configuration.

Community Votes

C
50%
D
50%

50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests mobility data path troubleshooting between 9800 and AireOS; the trap is confusing control path status with a data DTLS encryption mismatch.

This 300-425 question examines why the data path fails between a Catalyst 9800-CL and an AireOS 5520 while the control path remains up. The correct answer is C: data DTLS is disabled on the AireOS 5520, causing a mismatch in mobility data path encryption.

Many candidates choose D, assuming the 9800-CL is missing data-link-encryption, but the exhibit shows data-dtls explicitly disabled on the AireOS 5520.

Community Discussion (3 comments)

Reinier_veen 👍 1 Selected: D
According to Question 87 this should be D,
Farhad123 👍 1 Selected: C
config mobility group member data-dtls 00:1e:14:08:fb:ff disable
Farhad123 👍 2
C. is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The mobility control path between the 9800-CL and the AireOS 5520 is up, meaning UDP 16666 is reachable and the mobility group member configuration is valid. The exhibit shows the AireOS 5520 command config mobility group member data-dtls 00:1e:14:08:fb:ff disable, which turns off DTLS encryption for the data path (UDP 16667) toward the 9800-CL peer. Because the 9800-CL uses data DTLS by default, the mismatch prevents the data path from establishing even though control messages still flow. Enabling data DTLS on the 5520 (or disabling it on the 9800-CL) would bring the data path up. Therefore option C correctly identifies the disabled data-dtls setting on the AireOS side as the cause.

Why the Other Options Are Wrong

Option A is wrong because an incorrect certificate hash would also break data path establishment, but the exhibit shows an explicit "disable" command rather than a wrong hash value; the hash is not the issue when DTLS is turned off entirely. Option B is wrong because encrypted mobility is a control path encryption feature, and the control path is already up, so it cannot explain the data path failure. Option D is wrong because the 9800-CL does not need an additional data-link-encryption configuration when the AireOS side has data DTLS disabled; the mismatch is caused by the AireOS 5520 disabling data DTLS, not by a missing line on the 9800-CL. In fact, the 9800-CL default is to have data DTLS enabled, so the AireOS 5520's disabled state is the outlier.

Community Comment Notes

Farhad123 directly quoted the AireOS command "config mobility group member data-dtls 00:1e:14:08:fb:ff disable" and voted for C, which aligns with the exhibit's explicit DTLS disable. Reinier_veen referenced Question 87 to argue for D, but that scenario involves a different configuration where the 9800-CL is missing data-link-encryption; here the exhibit clearly shows the AireOS 5520 disabling data-dtls. The community is split 50/50, but the specific command in the exhibit makes C the stronger answer. No other commenter provided a contradictory configuration detail.

Exam Strategy

Focus on the data path vs control path distinction: control path uses UDP 16666 and confirms peer reachability, while data path uses UDP 16667 and depends on matching data DTLS settings. Check the AireOS data-dtls disable command in the exhibit before assuming a 9800 missing config.

Frequently Asked Questions

Why is option D wrong if the 9800-CL lacks data-link-encryption?

The exhibit explicitly shows data-dtls disabled on the AireOS 5520; the 9800-CL default data DTLS state is enabled, so the mismatch originates on the AireOS side.

How do I fix the data path between 9800-CL and AireOS 5520?

Enable data DTLS on the AireOS 5520 with config mobility group member data-dtls <mac> <hash>, or disable data DTLS on the 9800-CL to match.

Related Analysis

← Back to 300-425 Study Guide