WLC CPU ACL Rules for IPv4 Traffic

Implement Control Plane ACLs on the controller
Answer Correct answer: D — Allow RRM ports 12124–12125 and 12134–12135 at the top of the CPU ACL to prevent default blocking.

An engineer configures an ACL on a Cisco WLC v8.7. The engineer must control Pv4 traffic to the CPU of the controller. Which rules should be added at the top of the ACL to control IPv4 traffic?

  1. Allow mobility ports 16666, 16667, and 16668.
  2. Deny mobility ports 16666, 16667, and 16668.
  3. Deny RRM ports 12124–12125 and 12134–12135.
  4. Allow RRM ports 12124–12125 and 12134–12135. Correct Answer

Community Votes

D
50%
A
50%

50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

On a Cisco WLC, RRM ports are blocked by default in a CPU ACL, so they must be explicitly permitted at the top of the list to maintain AP communication.

Configuring a CPU ACL on a Cisco WLC requires explicitly allowing specific RRM ports to prevent them from being blocked by default. This page establishes that allowing RRM ports at the top of the ACL is the correct configuration for IPv4 CPU traffic control.

Choosing to allow mobility ports (Option A) instead of RRM ports, misunderstanding which service ports are blocked by default and require explicit top-of-list permission.

Community Discussion (3 comments)

rrahim 👍 1 Selected: A
When configuring an ACL on a Cisco WLC to control IPv4 traffic to the CPU, it is critical to allow mobility traffic to ensure proper communication between controllers in a mobility group. Here's why: Mobility Ports (16666, 16667, and 16668): These ports are used for communication between controllers in a mobility group. Blocking these ports can disrupt controller-to-controller communication, leading to issues such as client roaming failures. Therefore, the ACL must include rules to allow traffic on these ports at the top of the ACL to ensure uninterrupted mobility operations.
Le91 👍 1
Before you apply ACL rules, ensure that you have explicitly set the following RRM ports to allow in the CPU ACL: 12124-12125 12134-12135 Also ensure that you add these ACL rules specifically at the top of the ACL list. If you do not set these RRM ports to allow, the ports are blocked by default
Le91 👍 1 Selected: D
D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When configuring a CPU ACL on a Cisco WLC to control IPv4 traffic, Radio Resource Management (RRM) ports are implicitly blocked by default. To ensure APs can communicate with the WLC for RRM functions, you must explicitly add rules to permit RRM ports 12124–12125 and 12134–12135. These allow rules must be placed at the top of the ACL to ensure they are processed before any broader deny statements.

Why the Other Options Are Wrong

Options A and B focus on mobility ports (16666, 16667, and 16668), which are not the ports blocked by default that require explicit top-of-list permission in a CPU ACL context. Option C suggests denying RRM ports, which would intentionally break AP-to-controller RRM communication and is the exact opposite of the required configuration.

Community Comment Notes

As Le91 noted, "If you do not set these RRM ports to allow, the ports are blocked by default" and they must be added specifically at the top of the ACL list. This aligns with the official Cisco configuration guidelines for CPU ACLs, overriding the confusion caused by mobility ports.

Official Reference

Exam Strategy

For WLC CPU ACL questions, remember that RRM ports are blocked by default and must be explicitly allowed at the top of the ACL. Do not confuse them with mobility ports, which do not require this specific top-of-list explicit allow rule.

Related Analysis

← Back to 300-430 Study Guide