Which FlexConnect state rejects new users but keeps existing ones active?
When a branch location loses connectivity, which Cisco FlexConnect state rejects new users but allows existing users to function normally?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your knowledge of FlexConnect state transitions during WAN loss; the trap is confusing 'Authentication-Down/Switch-Local' with 'Authentication-Down/Switching-Down,' which drops all clients.
When a FlexConnect AP loses WAN connectivity, the Authentication-Down/Switch-Local state preserves existing client sessions while denying new authentications and switching traffic locally. Community consensus (100% votes for A) confirms this is the correct behavior for branch resilience.
Many candidates choose 'Authentication-Down/Switching-Down' because they assume all services halt when the WAN link fails; however, Switch-Local keeps existing clients forwarding traffic locally while only new authentications are rejected.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Cisco FlexConnect, the Authentication-Down/Switch-Local state is triggered when the AP loses connectivity to the WLC but still has local switching enabled. Existing client sessions remain active and continue forwarding data locally, while any new authentication attempts are rejected. This behavior ensures branch users already connected are not disrupted during an outage. Cisco documentation explicitly states this mode is valid only in standalone mode and maintains existing connections while denying new ones.Why the Other Options Are Wrong
Authentication-Down/Switching-Down (B) drops both new and existing clients because local switching is disabled, making it the most common wrong choice. Authentication-Central/Switch-Local (C) requires WAN connectivity for authentication, so it cannot function when the branch is disconnected. Authentication-Local/Switch-Local (D) allows both new and existing users to authenticate and switch locally, which contradicts the scenario requirement of rejecting new users.Community Comment Notes
Comment [1] links directly to the Cisco 9800 configuration guide confirming the Authentication-Down/Switch-Local behavior. Comment [2] provides a concise summary: maintain existing connections, deny new connections, exchange traffic locally, then resume operations once the WAN link is restored. Comment [3] notes similarity to other FlexConnect state questions, reminding candidates to distinguish between switching-down and switching-local modes.Official Reference
Exam Strategy
When a question describes a WAN outage scenario, immediately map the keywords 'existing users continue, new users rejected' to Authentication-Down/Switch-Local. Eliminate any option containing 'Switching-Down' if the scenario implies clients remain connected.
Related Analysis
Practice All 350-401 Questions
Access 218 questions with complete answers and detailed explanations.
View Full 350-401 Practice Test →