Why Won't Guests Authenticate on a Locally Authenticated FlexConnect Guest LAN?
An engineer set up a local authenticated Cisco FlexConnect AP with a guest LAN. Guests report not being able to authenticate. Which configuration must be changed on the WLAN for guests to be able to authenticate?
Community Votes
67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests whether you know that FlexConnect local authentication does not support a guest LAN WLAN and that the WLAN must be changed to central authentication; the trap is reaching for the backup RADIUS server option that Cisco documents for FlexConnect APs in standalone 802.1X EAP deployments.
A Cisco FlexConnect AP running local authentication cannot authenticate users on a guest LAN WLAN, because the guest LAN feature relies on the WLC's guest handling rather than the AP's local user database. The WLAN must be switched to central authentication for guests to log in, which makes answer C the correct choice for exam 300-430.
Most candidates choose D (backup RADIUS server) after reading the Cisco note that FlexConnect APs in standalone mode use the backup RADIUS server for 802.1X EAP authentication. That note concerns standalone EAP behavior, not a guest LAN WLAN whose authentication mode is set locally on the AP and therefore never reaches the WLC's guest services.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The scenario describes a FlexConnect AP whose WLAN is configured for local authentication, meaning the AP itself (not the controller) is responsible for authenticating clients. Cisco's FlexConnect restrictions do not allow the guest LAN feature to operate with AP-local authentication, because a guest LAN depends on the controller's guest user database, web policy, and central processing of guest logins. Guests therefore cannot authenticate until the WLAN is changed from local authentication to central authentication, so the WLC performs the authentication instead of the AP. Choosing central authentication is a WLAN-level change, which matches the question's wording that the configuration "must be changed on the WLAN."Why the Other Options Are Wrong
AAA override (A) only lets a RADIUS server return per-user attributes such as VLAN, QoS, or ACL to override WLAN settings, so it has no bearing on why guests fail to authenticate at all. RADIUS NAC (B) is a WLC state used with ISE posture and NAC authorization, again unrelated to guest authentication on a FlexConnect guest LAN. Backup RADIUS server (D) is the popular distractor: Cisco documents that FlexConnect APs in standalone mode use the backup RADIUS server configuration to support 802.1X EAP authentication, but this question never mentions standalone mode, and no RADIUS server change can compensate for a WLAN that is set to local authentication while hosting a guest LAN.Community Comment Notes
Ocsicccnp voted for D and cited the documentation line that "the controller uses its primary RADIUS servers," along with the following sentence about 802.1X EAP support on FlexConnect APs; that passage explains how a standalone FlexConnect AP reaches RADIUS servers, which is a different problem from a guest LAN that should not be using AP-local authentication in the first place. MaxMusti posted the Cisco 7.5 configuration guide PDF to argue for RADIUS NAC, but that document does not make NAC a requirement for guest authentication on a guest LAN. rrahim argued correctly that in a FlexConnect deployment with a guest LAN "the WLAN authentication method must be set to central authentication," which is the change that actually restores guest logins.Official Reference
Exam Strategy
For FlexConnect questions, first classify the feature: local switching, local authentication, and guest LAN each have documented restrictions, and the answer is usually the WLAN setting that removes the unsupported combination. If the stem names a guest LAN, expect central authentication (or central switching) rather than any RADIUS server option, even though the backup RADIUS server is the more popular pick.
Frequently Asked Questions
Why can't a locally authenticated FlexConnect AP serve a guest LAN WLAN?
Local authentication runs on the AP with its own user database and does not support the guest LAN feature, which depends on the controller's guest services for the login.
Why isn't the backup RADIUS server the fix for this guest LAN problem?
Backup RADIUS servers on the WLC matter when a FlexConnect AP operates in standalone mode for 802.1X EAP; they do not change how a guest LAN WLAN authenticates.