Which RADIUS Service-Type Gives Read-Only WLC Management Access?

Implement device access controls (including RADIUS and TACACS+)
Answer Correct answer: A — Configure the RADIUS Service-Type attribute as NAS Prompt to grant read-only WLC management access.

An engineer set up RADIUS for WLC management to harden the configuration. Read-only access must be provided to a user. Which Service-Type attribute must be configured on the RADIUS server to meet this requirement?

  1. NAS Prompt Correct Answer
  2. Administrative
  3. Call Check
  4. Callback Login

Community Votes

A
83%
B
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This item tests RADIUS Service-Type authorization values for WLC management users; the trap is choosing Administrative (6), which grants read-write access, or confusing legacy dial-up values Call Check and Callback Login with controller authorization.

Configuring RADIUS for WLC management requires the correct Service-Type attribute to enforce read-only privileges on the controller. On Cisco WLCs, Service-Type NAS Prompt (7) is the documented value for read-only management access, making option A correct.

Many engineers choose Administrative (B) because the word implies granting administrator access, but on the Cisco WLC that Service-Type maps to read-write management, while NAS Prompt is the documented read-only value.

Community Discussion (6 comments)

rrahim 👍 1 Selected: A
To provide read-only access to a user for WLC (Wireless LAN Controller) management via RADIUS, the Service-Type attribute must be set to NAS Prompt on the RADIUS server. This attribute allows the user to access the WLC in a read-only mode, preventing any configuration changes. Explanation of the options: A. NAS Prompt: This is correct. The NAS Prompt Service-Type attribute provides read-only access to the WLC, allowing the user to view configurations but not modify them. B. Administrative: This Service-Type attribute grants full administrative access, including the ability to modify configurations, which is not suitable for read-only access. C. Call Check: This attribute is used for call verification and is unrelated to WLC management access. D. Callback Login: This attribute is used for callback authentication and is not relevant for providing read-only access to the WLC.
rrahim 👍 1 Selected: B
The Service-Type attribute in RADIUS defines the type of service being provided to the user. For WLC management access, the following values are relevant: Administrative (6): This value grants administrative access to the WLC. However, the level of access (read-only or read-write) is further controlled by the Privilege Level attribute. To enforce read-only access, the Privilege Level attribute should be set to 1 (read-only) in conjunction with the Service-Type attribute set to Administrative. Why not the other options? A. NAS Prompt: This is not relevant for WLC management access.
netwkguy99 👍 1 Selected: A
The correct answer is: A. NAS Prompt Explanation: In RADIUS, the Service-Type attribute defines the type of service to be provided to the user. For read-only access on a Wireless LAN Controller (WLC), the Service-Type should be set to NAS Prompt. This value typically provides the user with a lower level of access, such as read-only, as opposed to full administrative access, which would be set by using the Administrative service type. By setting the Service-Type to NAS Prompt, the user is granted read-only access to the WLC, which aligns with the requirement.
claudio392 👍 1 Selected: A
Answer is A NAS Prompt
tachy_22 👍 1
I agree with baddieandyz94
baddieandyz94 👍 2 Selected: A
Answer is A https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/71989-manage-wlc-users-radius.html#toc-hId--1799525129

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

On the Cisco WLC, RADIUS management authorization is driven by the Service-Type attribute returned in the RADIUS Access-Accept. Cisco documentation for managing WLC users with RADIUS maps Service-Type value 7, NAS Prompt, to read-only (monitor) access for controller management users, which is precisely what the question requires. Value 6, Administrative, is the read-write management service type and would allow configuration changes. The Cisco 71989 WLC-RADIUS document that community members cite explicitly supports NAS Prompt for read-only access, so option A is the correct configuration.

Why the Other Options Are Wrong

Administrative (B) grants full read-write management access on the WLC, which directly contradicts the read-only requirement. Call Check (C) is a RADIUS Service-Type used for call-check and roaming authorization scenarios in dial-up/AAA environments, not for controller GUI or CLI privileges. Callback Login (D) is a legacy dial-up value that asks the NAS to call the user back at a specified number and has no role in read-only WLC management authorization.

Community Comment Notes

Several commenters, including rrahim and netwkguy99, explain that NAS Prompt is the read-only WLC service type tied to the Service-Type attribute, matching the vendor's documented mapping. baddieandyz94 links to Cisco's 71989 WLC-RADIUS management document, which is the authoritative source for these Service-Type values and is why the A consensus formed. One rrahim post argues Administrative could be limited by a Privilege Level attribute, but WLC management read-only versus read-write is determined through the Service-Type mapping, so that reasoning does not override the documented NAS Prompt behavior.

Official Reference

Exam Strategy

Memorize the short list of RADIUS Service-Type values Cisco uses for WLC management: NAS Prompt for read-only, Administrative for read-write, and treat Call Check/Callback Login as dial-up legacy values. When a question says read-only, look for NAS Prompt rather than any option containing the word 'administrative'.

Frequently Asked Questions

Why does Service-Type Administrative (6) grant read-write WLC access?

Cisco maps Administrative (6) to read-write management privileges on the WLC, allowing configuration changes, so it cannot satisfy a read-only requirement.

Is Callback Login ever used for read-only WLC GUI access?

No. Callback Login (D) is a legacy dial-up Service-Type that requests a callback number; it is not used for WLC management authorization levels.

Related Analysis

← Back to 300-430 Study Guide