Which ACL Type Enables FlexConnect Split Tunneling?
Split Tunneling must be configured for traffic sent by the client to be classified based on packet content, using an ACL. To accomplish this, the packets must be either locally switched from Cisco FlexConnect AP or centrally-switched over CAPWAP. Which type of ACL must be configured to accomplish this switching?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests which ACL type handles traffic classification for FlexConnect split tunneling, and the trap is assuming a standard WLAN or interface ACL applies to locally switched traffic.
FlexConnect split tunneling requires classifying client traffic by packet content so it can be locally switched at the FlexConnect AP or centrally switched over CAPWAP. This page confirms that a FlexConnect ACL is the ACL type that performs this classification.
Many candidates pick the WLAN ACL because ACLs are commonly applied at the WLAN level on the controller, but a WLAN ACL does not classify traffic that is locally switched at a FlexConnect AP.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A FlexConnect ACL is the ACL type designed specifically for FlexConnect deployments, and it is what allows client traffic to be classified by packet content so it can be locally switched at the FlexConnect AP or centrally switched over CAPWAP. This dual behavior is exactly what split tunneling needs: some traffic is dropped off locally at the branch and the rest is tunneled back to the controller. The ACL is applied on the FlexConnect AP/WLAN configuration so the classification decision happens where the traffic actually egresses. That is why C is the only option that matches the requirement in the question.Why the Other Options Are Wrong
An interface ACL is applied to a controller interface and governs traffic arriving on or leaving that interface; it cannot classify client traffic for local switching at a FlexConnect AP. A CPU ACL protects the controller's CPU by filtering traffic destined to the controller itself, which has nothing to do with split-tunnel client data classification. A WLAN ACL is applied to the WLAN and is used for centrally switched traffic, but it does not provide the local-versus-central split behavior described in the question. None of these three options deliver the FlexConnect-specific local/central switching decision, so they are all incorrect.Community Comment Notes
As rrahim explains, the FlexConnect ACL "allows traffic to be locally switched at the FlexConnect AP or centrally switched over CAPWAP, depending on the ACL rules," which mirrors the exam's wording about split tunneling. casterJR adds that FlexConnect ACLs control data traffic to and from wireless clients and are particularly useful with locally switched traffic on a FlexConnect AP, then states plainly that "Correct answer is C." The unanimous community vote for C agrees with the vendor's FlexConnect documentation and with the question's own description of the requirement.Exam Strategy
When a 300-430 question mentions local switching at a FlexConnect AP alongside an ACL, anchor on the FlexConnect ACL rather than a generic WLAN, interface, or CPU ACL. Read the requirement for "locally switched or centrally switched over CAPWAP" as the vendor's signature phrase for FlexConnect ACL functionality.
Frequently Asked Questions
Why is a WLAN ACL not the right choice for FlexConnect split tunneling?
A WLAN ACL is applied at the WLAN level for centrally switched traffic; only a FlexConnect ACL controls the local-versus-central switching decision by packet content at the FlexConnect AP.
Can a FlexConnect ACL classify traffic that is centrally switched over CAPWAP?
Yes. FlexConnect ACLs classify and control traffic whether it is locally switched at the FlexConnect AP or centrally switched back to the controller over CAPWAP.