Which FlexConnect State Keeps Branch Users Online After WLC Loss?

Deploy FlexConnect components such as switching and operating modes Deploy FlexConnect capabilities
Answer Correct answer: B — Implement Authentication Local/Switch Local so the FlexConnect AP terminates 802.1X locally and switches client traffic at the branch when the WLC is unreachable.

An engineer must deploy FlexConnect APs to a branch office. If the connection to the WLC fails and 802.1X authentication is available, users must stay connected to the AP. Which FlexConnect state should be implemented?

  1. Authentication Central/Switch Central
  2. Authentication Local/Switch Local Correct Answer
  3. Authentication Central/Switch Local
  4. Authentication Local/Switch Central

Community Votes

B
75%
C
25%

75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests FlexConnect authentication versus switching modes during a controller outage; the trap is assuming that a central authentication mode can still validate 802.1X clients once the WLC tunnel is down.

FlexConnect branch APs must survive a WLC outage while 802.1X is still reachable, and only Authentication Local with Switch Local lets the AP terminate authentication and switch client traffic itself. This page confirms why option B is the exam answer and why the central modes break during a CAPWAP failure.

Picking Authentication Central/Switch Local (C) because local switching sounds like enough to keep users online; with Authentication Central the AP still depends on the WLC to talk to the AAA server, so clients cannot complete 802.1X when the controller is unreachable.

Community Discussion (4 comments)

rrahim 👍 1 Selected: B
It is either B or C FlexConnect is designed for branch deployments where APs can continue functioning even if they lose connectivity to the centralized WLC. To ensure users remain connected when the WLC connection fails but 802.1X authentication is still available, the best option is Authentication Local / Switch Local. Authentication Local → The AP handles 802.1X authentication locally, allowing clients to authenticate even if the WLC is unreachable. Switch Local → The AP forwards client traffic directly to the local switch, reducing reliance on the WLC for data plane operations. Why not the other options? A. Authentication Central / Switch Central → Requires WLC connectivity for both authentication and switching. If the WLC fails, clients will be disconnected. C. Authentication Central / Switch Local → Still relies on the WLC for authentication, meaning users will be disconnected if the WLC is unavailable. D. Authentication Local / Switch Central → Authentication works locally, but traffic is still sent back to the WLC, which can create problems if the WLC is down.
rrahim 👍 1 Selected: C
To ensure that users remain connected to the FlexConnect APs even if the connection to the Wireless LAN Controller (WLC) fails, the Authentication Central/Switch Local configuration should be implemented. This configuration provides the following benefits: Authentication Central: User authentication (e.g., 802.1X) is handled by the WLC when it is reachable. This ensures centralized control over authentication policies. Switch Local: Traffic is forwarded locally at the AP, even if the WLC is unreachable. This allows users to stay connected and continue accessing local resources during a WLC outage. This setup is ideal for branch offices where maintaining connectivity during WLC failures is critical.
rrahim 👍 1 Selected: B
To ensure that users remain connected to the FlexConnect APs even if the connection to the Wireless LAN Controller (WLC) fails, the Authentication Central/Switch Local configuration should be implemented. This configuration provides the following benefits: Authentication Central: User authentication (e.g., 802.1X) is handled by the WLC when it is reachable. This ensures centralized control over authentication policies. Switch Local: Traffic is forwarded locally at the AP, even if the WLC is unreachable. This allows users to stay connected and continue accessing local resources during a WLC outage. This setup is ideal for branch offices where maintaining connectivity during WLC failures is critical.
Le91 👍 1 Selected: B
C is also not wrong as it mention that existing users should stay connected. B would be the best options for new sessions as far as 802.1X stays online

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

FlexConnect Authentication Local means the AP itself acts as the 802.1X authenticator, sending RADIUS requests straight to the AAA server instead of proxying them through the WLC. Switch Local (local switching) means client data is bridged at the branch and never has to traverse the CAPWAP tunnel to the controller. When the WLC connection fails and the AAA/802.1X infrastructure is still available, this pairing is the only one where both the control plane for authentication and the data plane for user traffic survive locally. That is exactly the branch-office survivability model FlexConnect is designed for, which is why option B is the answer.

Why the Other Options Are Wrong

Option A (Authentication Central/Switch Central) fails on both counts: authentication is proxied by the WLC and traffic is tunneled to the WLC, so a controller outage breaks authentication and the data path together. Option C (Authentication Central/Switch Local) keeps the data path alive but still relies on the controller for 802.1X, meaning new clients cannot authenticate after the WLC goes down. Option D (Authentication Local/Switch Central) fixes authentication but sends client traffic through the very CAPWAP tunnel that is now down, so users lose connectivity. Only local authentication plus local switching removes the WLC from both the authentication decision and the forwarding decision.

Community Comment Notes

One commenter, rrahim, first argued both B and C were plausible and even wrote up the case for Authentication Central/Switch Local, but ultimately selected B. Another commenter, Le91, captured the nuance well by noting that C is not entirely wrong for already-associated clients, while "B would be the best options for new sessions as far as 802.1X stays online" — which matches the question's requirement that users stay connected with authentication still available. The vote split (B: 75, C: 25) reflects that exact confusion between keeping existing sessions alive and keeping the branch fully operational.

Exam Strategy

Memorize the FlexConnect matrix as two independent decisions: Authentication Local/Central controls whether the AP or the WLC talks to the AAA server, and Switch Local/Central controls whether frames are bridged at the branch or tunneled to the WLC. For any scenario describing a WLC outage with the AAA server still reachable, both answers must fall on the local side.

Frequently Asked Questions

Why is Authentication Central/Switch Local wrong when the WLC fails?

With Authentication Central the AP still proxies 802.1X through the WLC, so once the controller is unreachable new clients cannot authenticate even though local switching keeps the data path alive.

Does Switch Local alone guarantee connectivity if the WLC is unreachable?

No. Local switching only keeps frames at the branch; if authentication is Central, clients still depend on the WLC to reach the AAA server and will fail to join.

More 300-430 FAQ →

Related Analysis

← Back to 300-430 Study Guide