Cisco WLC AP Authentication for Rogue Containment
A wireless network has two RF groups where Cisco WLCs are joined. APs are associated with different controllers using the round-robin approach. Rogue containment must be deployed in all controllers, but the network must not be affected by any RRM neighbor packets sent by friendly APs. Which AP authentication protection type must be enabled?
Community Votes
75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the specific Cisco WLC feature that stops RRM neighbor packets from friendly APs from triggering rogue containment; the trap is confusing it with generic AP security or a non-existent 'AP Wireless Protection Rules' feature.
In a multi-controller Cisco WLC network with separate RF groups, AP Authentication prevents rogue containment from acting on RRM neighbor packets sent by friendly APs. The correct protection type is AP Authentication (A).
Many candidates choose AP Wireless Protection Rules (B) because it sounds like a granular policy, but Cisco WLC does not offer a feature by that name; AP Authentication is the actual setting under Security > AP Policies.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AP Authentication is the Cisco WLC feature designed to validate access points before they join the controller. When enabled, the controller checks the AP's pre-shared key or certificate. In a deployment with multiple controllers in separate RF groups, an AP associated to one controller may be seen by another controller as a rogue AP. However, if AP Authentication is enabled, the controller recognizes the AP as friendly and does not trigger rogue containment, even if it receives RRM neighbor packets. This matches the requirement that rogue containment be deployed on all controllers without affecting friendly APs, as confirmed by the Cisco 8.5 RRM configuration guide.Why the Other Options Are Wrong
Option B, "AP Wireless Protection Rules," is not a valid Cisco WLC feature; the WLC has "Wireless Protection Policies" but no such rule set. Option C, "AP Security," is too generic and does not correspond to a specific setting that prevents friendly APs from being contained. Option D, "AP Access Control," refers to access control lists or authorization, not to AP authentication for rogue prevention. None of these options provide the mechanism that distinguishes authenticated APs from rogues.Community Comment Notes
One commenter, 80b7716, correctly points to the Cisco 8.5 RRM guide as the reference and selects A. Another, rrahim, explains that AP Authentication ensures only authorized APs join the network, preventing rogue APs from connecting. largestyle questions where the term "AP Wireless Protection Rules" comes from, noting no source can be found. robi1020 argues for B as providing "more granular control," but this feature does not exist in Cisco WLC; the correct setting remains AP Authentication.Official Reference
Exam Strategy
When studying rogue detection and containment, memorize the exact Cisco WLC GUI terms: AP Authentication is under Security > AP Policies, while rogue policies are under Security > Wireless Protection Policies. In multi-controller scenarios, always consider how controllers authenticate APs across RF groups to avoid false containment.
Frequently Asked Questions
Why is AP Wireless Protection Rules not the correct answer?
Cisco WLC does not have a feature called AP Wireless Protection Rules; AP Authentication is the actual setting under Security > AP Policies that prevents friendly APs from being treated as rogues.
How does AP Authentication prevent RRM neighbor packets from triggering containment?
When AP Authentication is enabled, the controller validates APs via pre-shared key or certificate, so it recognizes friendly APs from other RF groups and does not contain them.