Which RADIUS Service-Type Gives Read-Only WLC Management Access?
An engineer set up RADIUS for WLC management to harden the configuration. Read-only access must be provided to a user. Which Service-Type attribute must be configured on the RADIUS server to meet this requirement?
Community Votes
83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This item tests RADIUS Service-Type authorization values for WLC management users; the trap is choosing Administrative (6), which grants read-write access, or confusing legacy dial-up values Call Check and Callback Login with controller authorization.
Configuring RADIUS for WLC management requires the correct Service-Type attribute to enforce read-only privileges on the controller. On Cisco WLCs, Service-Type NAS Prompt (7) is the documented value for read-only management access, making option A correct.
Many engineers choose Administrative (B) because the word implies granting administrator access, but on the Cisco WLC that Service-Type maps to read-write management, while NAS Prompt is the documented read-only value.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
On the Cisco WLC, RADIUS management authorization is driven by the Service-Type attribute returned in the RADIUS Access-Accept. Cisco documentation for managing WLC users with RADIUS maps Service-Type value 7, NAS Prompt, to read-only (monitor) access for controller management users, which is precisely what the question requires. Value 6, Administrative, is the read-write management service type and would allow configuration changes. The Cisco 71989 WLC-RADIUS document that community members cite explicitly supports NAS Prompt for read-only access, so option A is the correct configuration.Why the Other Options Are Wrong
Administrative (B) grants full read-write management access on the WLC, which directly contradicts the read-only requirement. Call Check (C) is a RADIUS Service-Type used for call-check and roaming authorization scenarios in dial-up/AAA environments, not for controller GUI or CLI privileges. Callback Login (D) is a legacy dial-up value that asks the NAS to call the user back at a specified number and has no role in read-only WLC management authorization.Community Comment Notes
Several commenters, including rrahim and netwkguy99, explain that NAS Prompt is the read-only WLC service type tied to the Service-Type attribute, matching the vendor's documented mapping. baddieandyz94 links to Cisco's 71989 WLC-RADIUS management document, which is the authoritative source for these Service-Type values and is why the A consensus formed. One rrahim post argues Administrative could be limited by a Privilege Level attribute, but WLC management read-only versus read-write is determined through the Service-Type mapping, so that reasoning does not override the documented NAS Prompt behavior.Official Reference
Exam Strategy
Memorize the short list of RADIUS Service-Type values Cisco uses for WLC management: NAS Prompt for read-only, Administrative for read-write, and treat Call Check/Callback Login as dial-up legacy values. When a question says read-only, look for NAS Prompt rather than any option containing the word 'administrative'.
Frequently Asked Questions
Why does Service-Type Administrative (6) grant read-write WLC access?
Cisco maps Administrative (6) to read-write management privileges on the WLC, allowing configuration changes, so it cannot satisfy a read-only requirement.
Is Callback Login ever used for read-only WLC GUI access?
No. Callback Login (D) is a legacy dial-up Service-Type that requests a callback number; it is not used for WLC management authorization levels.