Why Won't Guests Authenticate on a Locally Authenticated FlexConnect Guest LAN?

Deploy FlexConnect capabilities Deploy FlexConnect components such as switching and operating modes
Answer Correct answer: C — Set the guest LAN WLAN to central authentication so FlexConnect guests authenticate through the WLC instead of AP-local authentication.

An engineer set up a local authenticated Cisco FlexConnect AP with a guest LAN. Guests report not being able to authenticate. Which configuration must be changed on the WLAN for guests to be able to authenticate?

  1. AAA override
  2. RADIUS NAC
  3. central authentication Correct Answer
  4. backup RADIUS server

Community Votes

D
67%
C
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests whether you know that FlexConnect local authentication does not support a guest LAN WLAN and that the WLAN must be changed to central authentication; the trap is reaching for the backup RADIUS server option that Cisco documents for FlexConnect APs in standalone 802.1X EAP deployments.

A Cisco FlexConnect AP running local authentication cannot authenticate users on a guest LAN WLAN, because the guest LAN feature relies on the WLC's guest handling rather than the AP's local user database. The WLAN must be switched to central authentication for guests to log in, which makes answer C the correct choice for exam 300-430.

Most candidates choose D (backup RADIUS server) after reading the Cisco note that FlexConnect APs in standalone mode use the backup RADIUS server for 802.1X EAP authentication. That note concerns standalone EAP behavior, not a guest LAN WLAN whose authentication mode is set locally on the AP and therefore never reaches the WLC's guest services.

Community Discussion (3 comments)

rrahim 👍 1 Selected: C
In a Cisco FlexConnect deployment, when a local authenticated AP is configured with a guest LAN, the WLAN authentication method must be set to central authentication to ensure that guest users can authenticate properly. FlexConnect APs can operate in two modes: Central Switching: All traffic is tunneled back to the Wireless LAN Controller (WLC) for processing. Local Switching: Traffic is forwarded locally at the AP, but authentication is still handled centrally by the WLC. For guest access, central authentication is typically required because: Guest authentication often relies on the WLC to handle AAA (Authentication, Authorization, and Accounting) services. Local authentication on the AP may not support the required guest authentication mechanisms (e.g., web authentication, RADIUS, etc.).
Ocsicccnp 👍 2 Selected: D
When FlexConnect access points are connected to the controller (rather than in standalone mode), the controller uses its primary RADIUS servers and accesses them in the order specified on the RADIUS Authentication Servers page or in the config radius auth add CLI command (unless the server order is overridden for a particular WLAN). However, to support 802.1X EAP authentication, FlexConnect access points in standalone mode need to have their own backup RADIUS server to authenticate clients.
MaxMusti 👍 2
https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-5/configuration-guide/b_cg75/b_cg75_chapter_0110000.pdf --> B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario describes a FlexConnect AP whose WLAN is configured for local authentication, meaning the AP itself (not the controller) is responsible for authenticating clients. Cisco's FlexConnect restrictions do not allow the guest LAN feature to operate with AP-local authentication, because a guest LAN depends on the controller's guest user database, web policy, and central processing of guest logins. Guests therefore cannot authenticate until the WLAN is changed from local authentication to central authentication, so the WLC performs the authentication instead of the AP. Choosing central authentication is a WLAN-level change, which matches the question's wording that the configuration "must be changed on the WLAN."

Why the Other Options Are Wrong

AAA override (A) only lets a RADIUS server return per-user attributes such as VLAN, QoS, or ACL to override WLAN settings, so it has no bearing on why guests fail to authenticate at all. RADIUS NAC (B) is a WLC state used with ISE posture and NAC authorization, again unrelated to guest authentication on a FlexConnect guest LAN. Backup RADIUS server (D) is the popular distractor: Cisco documents that FlexConnect APs in standalone mode use the backup RADIUS server configuration to support 802.1X EAP authentication, but this question never mentions standalone mode, and no RADIUS server change can compensate for a WLAN that is set to local authentication while hosting a guest LAN.

Community Comment Notes

Ocsicccnp voted for D and cited the documentation line that "the controller uses its primary RADIUS servers," along with the following sentence about 802.1X EAP support on FlexConnect APs; that passage explains how a standalone FlexConnect AP reaches RADIUS servers, which is a different problem from a guest LAN that should not be using AP-local authentication in the first place. MaxMusti posted the Cisco 7.5 configuration guide PDF to argue for RADIUS NAC, but that document does not make NAC a requirement for guest authentication on a guest LAN. rrahim argued correctly that in a FlexConnect deployment with a guest LAN "the WLAN authentication method must be set to central authentication," which is the change that actually restores guest logins.

Official Reference

Exam Strategy

For FlexConnect questions, first classify the feature: local switching, local authentication, and guest LAN each have documented restrictions, and the answer is usually the WLAN setting that removes the unsupported combination. If the stem names a guest LAN, expect central authentication (or central switching) rather than any RADIUS server option, even though the backup RADIUS server is the more popular pick.

Frequently Asked Questions

Why can't a locally authenticated FlexConnect AP serve a guest LAN WLAN?

Local authentication runs on the AP with its own user database and does not support the guest LAN feature, which depends on the controller's guest services for the login.

Why isn't the backup RADIUS server the fix for this guest LAN problem?

Backup RADIUS servers on the WLC matter when a FlexConnect AP operates in standalone mode for 802.1X EAP; they do not change how a guest LAN WLAN authenticates.

More 300-430 FAQ →

Related Analysis

← Back to 300-430 Study Guide