Autonomous AP 802.1X: Which Two RADIUS Details Must Be Configured?
An engineer needs to configure an autonomous AP for 802.1x authentication. To achieve the highest security an authentication server is used for user authentication. During testing, the AP fails to pass the user authentication request to the authentication server. Which two details need to be configured on the AP to allow communication between the server and the AP? (Choose two.)
Community Votes
100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests RADIUS client configuration on an autonomous AP; the trap is choosing user credentials or EAP-FAST PAC parameters instead of the server address and shared secret.
An autonomous AP must act as a RADIUS client for 802.1X user authentication. This page confirms that the RADIUS server IP address and shared secret are the two required details.
Selecting username/password (A) because it sounds like authentication; these are for AP management or supplicant credentials, not for AP-to-RADIUS communication.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The autonomous AP must act as a RADIUS client when it forwards 802.1X user authentication requests to the external authentication server. For that communication to work, the AP needs the RADIUS server's IP address so it knows where to send Access-Request packets, and it needs the shared secret that must match the secret configured on the RADIUS server. In Cisco autonomous AP configuration, these are the core RADIUS server parameters under the security or services RADIUS settings. Without either one, the AP cannot establish a trusted RADIUS exchange and the user authentication request never reaches the server. Therefore options C and D are the two required details.Why the Other Options Are Wrong
A username and password are used for AP management access or for an 802.1X supplicant identity, not for the RADIUS client-to-server authentication exchange, so option A does not solve the failed forwarding. The PAC encryption key in option B is associated with EAP-FAST provisioning and tunnel establishment, not with basic RADIUS server reachability for 802.1X user authentication. Option E, group name, may appear in AAA server group configuration, but it is not the detail that enables communication between the AP and the authentication server. Only the server IP address and the matching shared secret directly allow the AP to pass authentication requests to the RADIUS server.Community Comment Notes
As rrahim explained, the AP needs the RADIUS IP address to send authentication requests and the shared secret to secure communication with the server, and both must match what is configured on the RADIUS server. Le91 and MaxMusti also marked the provided answer as correct, reinforcing the CD consensus. No commenter argued for username/password, PAC key, or group name as the missing communication details. The community discussion aligns with the standard RADIUS client requirements for autonomous AP 802.1X deployments.Exam Strategy
When the stem asks what allows the AP to communicate with the authentication server, focus on RADIUS client parameters: server IP address and shared secret. User credentials and EAP-FAST PAC settings are distractors because they do not establish the AP-to-RADIUS transport.
Frequently Asked Questions
Why is the PAC encryption key not needed for autonomous AP 802.1X?
PAC is used with EAP-FAST for tunnel establishment; standard 802.1X RADIUS client communication only needs the server IP and shared secret.
Does the AP need a username and password for RADIUS authentication?
No. Those are for the AP's management login or an 802.1X supplicant, not for the AP-to-RADIUS server authentication exchange.