Which FlexConnect State Keeps Branch Users Online After WLC Loss?
An engineer must deploy FlexConnect APs to a branch office. If the connection to the WLC fails and 802.1X authentication is available, users must stay connected to the AP. Which FlexConnect state should be implemented?
Community Votes
75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests FlexConnect authentication versus switching modes during a controller outage; the trap is assuming that a central authentication mode can still validate 802.1X clients once the WLC tunnel is down.
FlexConnect branch APs must survive a WLC outage while 802.1X is still reachable, and only Authentication Local with Switch Local lets the AP terminate authentication and switch client traffic itself. This page confirms why option B is the exam answer and why the central modes break during a CAPWAP failure.
Picking Authentication Central/Switch Local (C) because local switching sounds like enough to keep users online; with Authentication Central the AP still depends on the WLC to talk to the AAA server, so clients cannot complete 802.1X when the controller is unreachable.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
FlexConnect Authentication Local means the AP itself acts as the 802.1X authenticator, sending RADIUS requests straight to the AAA server instead of proxying them through the WLC. Switch Local (local switching) means client data is bridged at the branch and never has to traverse the CAPWAP tunnel to the controller. When the WLC connection fails and the AAA/802.1X infrastructure is still available, this pairing is the only one where both the control plane for authentication and the data plane for user traffic survive locally. That is exactly the branch-office survivability model FlexConnect is designed for, which is why option B is the answer.Why the Other Options Are Wrong
Option A (Authentication Central/Switch Central) fails on both counts: authentication is proxied by the WLC and traffic is tunneled to the WLC, so a controller outage breaks authentication and the data path together. Option C (Authentication Central/Switch Local) keeps the data path alive but still relies on the controller for 802.1X, meaning new clients cannot authenticate after the WLC goes down. Option D (Authentication Local/Switch Central) fixes authentication but sends client traffic through the very CAPWAP tunnel that is now down, so users lose connectivity. Only local authentication plus local switching removes the WLC from both the authentication decision and the forwarding decision.Community Comment Notes
One commenter, rrahim, first argued both B and C were plausible and even wrote up the case for Authentication Central/Switch Local, but ultimately selected B. Another commenter, Le91, captured the nuance well by noting that C is not entirely wrong for already-associated clients, while "B would be the best options for new sessions as far as 802.1X stays online" — which matches the question's requirement that users stay connected with authentication still available. The vote split (B: 75, C: 25) reflects that exact confusion between keeping existing sessions alive and keeping the branch fully operational.Exam Strategy
Memorize the FlexConnect matrix as two independent decisions: Authentication Local/Central controls whether the AP or the WLC talks to the AAA server, and Switch Local/Central controls whether frames are bridged at the branch or tunneled to the WLC. For any scenario describing a WLC outage with the AAA server still reachable, both answers must fall on the local side.
Frequently Asked Questions
Why is Authentication Central/Switch Local wrong when the WLC fails?
With Authentication Central the AP still proxies 802.1X through the WLC, so once the controller is unreachable new clients cannot authenticate even though local switching keeps the data path alive.
Does Switch Local alone guarantee connectivity if the WLC is unreachable?
No. Local switching only keeps frames at the branch; if authentication is Central, clients still depend on the WLC to reach the AAA server and will fail to join.