WLC CPU ACL Rules for IPv4 Traffic
An engineer configures an ACL on a Cisco WLC v8.7. The engineer must control Pv4 traffic to the CPU of the controller. Which rules should be added at the top of the ACL to control IPv4 traffic?
Community Votes
50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
On a Cisco WLC, RRM ports are blocked by default in a CPU ACL, so they must be explicitly permitted at the top of the list to maintain AP communication.
Configuring a CPU ACL on a Cisco WLC requires explicitly allowing specific RRM ports to prevent them from being blocked by default. This page establishes that allowing RRM ports at the top of the ACL is the correct configuration for IPv4 CPU traffic control.
Choosing to allow mobility ports (Option A) instead of RRM ports, misunderstanding which service ports are blocked by default and require explicit top-of-list permission.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When configuring a CPU ACL on a Cisco WLC to control IPv4 traffic, Radio Resource Management (RRM) ports are implicitly blocked by default. To ensure APs can communicate with the WLC for RRM functions, you must explicitly add rules to permit RRM ports 12124–12125 and 12134–12135. These allow rules must be placed at the top of the ACL to ensure they are processed before any broader deny statements.Why the Other Options Are Wrong
Options A and B focus on mobility ports (16666, 16667, and 16668), which are not the ports blocked by default that require explicit top-of-list permission in a CPU ACL context. Option C suggests denying RRM ports, which would intentionally break AP-to-controller RRM communication and is the exact opposite of the required configuration.Community Comment Notes
As Le91 noted, "If you do not set these RRM ports to allow, the ports are blocked by default" and they must be added specifically at the top of the ACL list. This aligns with the official Cisco configuration guidelines for CPU ACLs, overriding the confusion caused by mobility ports.Official Reference
Exam Strategy
For WLC CPU ACL questions, remember that RRM ports are blocked by default and must be explicitly allowed at the top of the ACL. Do not confuse them with mobility ports, which do not require this specific top-of-list explicit allow rule.