Chapter 29 - Building a Wireless LAN Flashcards

1
Q

True or False. A VLAN is mapped to a WLAN.

A

True. A Dynamic Interface needs to be created for each WLAN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False. You can only access an APs management interface via Telnet or SSH.

A

False. You can also use HTTP and HTTPS. For LAPs you need to access the connected WLCs interface to manage it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the different types of physical ports on a WLC?

A
  • Service Port - Used for out-of-band management, system recovery, and initial boot functions. Always has to connect to a switch port that is in access mode. Also best practice to connect to an access port that is part of the management VLAN.
  • Distribution System Port - Used to connect the WLC to a DS for all AP data traffic. Normally connects to a switch port that is in trunk mode. All of these ports can be configured together as a single LAG (Link Aggregation Group) which allows for failover and load balancing.
  • Console Port - Used for out-of-band management, system recovery, and initial boot functions. Terminal emulator must be configured as 9600 baud rate, 8 data bits, 1 stop bit, in order to access. Can be RJ45 and/or USB
  • Redundancy port - Used to connect to a peer controller for high availability operation (failover).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or False. WLC LAGs support standard EtherChannel protocols (e.g. LACP, PAGP).

A

False. The switch they connect to must have its EtherChannel mode set to ‘on’.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the different types of interfaces/logical interfaces in a WLC?

A
  • Management Interface - IP used for in band management traffic such as RADIUS authentication (to login to the WLC), WLC to WLC communication, HTTP, HTTPS, and SSH sessons, SNMP, NTP, syslog, etc. Also used to terminate the CAPWAP tunnels between the controller and its APs. (CAPWAP type management and logging into the WLC to configure type management).
  • Redundancy Management Interface - The management IP of a redundant WLC that is part of a high availability pair of controllers. The active WLC uses the management interface address while the standy WLC uses the redundancy management address.
  • Virtual Interface - IP address facing wireless clients. Used when a client requests an IP and the WLC needs to provide an address from the correct pool as if it were the server (DHCP Relay), performing client web authentication, and supporting client mobility. The virtual interface IP address is only used for communications between the controller and wireless clients. It never appears as the source or destination address of a packet that goes out through the distribution ports and on to the local network. A commonly used address is 10.1.1.1 as it is not supposed to be routable and is also private. All WLCs in a single mobility group should have this IP as the same.
  • Service Port Interface - Bound to the service port and used for out-of-band management. Only port available when the WLC is booting.
  • Dynamic Interface - Used to connect a VLAN to a WLAN. For every WLAN created you must also create a Dynamic Interface. These must be part of different subnets.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Mobility Group?

A
  • A group of WLCs that define a seamless roaming area for clients, exchange information about said clients, and forward this information when roaming occurs between APs served by different WLCs. They also share information about their connected APs so that each controller does not treat other controller’s APs as rogue.
  • WLCs in the same mobility group should be configured with the same Virtual Interface IP.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many WLANs can a Cisco WLC support?

A

512, however, only 16 can be active at a time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How often are WLAN beacons sent?

A

10 times per second

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What do APs use to broadcast the existence of a WLAN?

A

Beacons

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

List downsides of having too many WLANs active at a time

A
  • The more WLANs there are, the more management beacons are sent, the less airtime there is for actual traffic to be sent by wireless clients
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False. EAP based wireless security systems require RADIUS/TACACs+ .

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When setting up a RADIUS server in a Cisco WLC, what are the two types of users that can be authenticated?

A
  • Network Users - Wireless Clients
  • Management - Administrators that will be configuring the WLC
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the security types available when configuring a WLAN on a Cisco WLC?

A
  • None - Open Authentication
  • WPA + WPA2 - Wifi protected access WPA or WPA2
  • 802.1x - EAP authentication with dynamic WEP
  • Static WEP - WEP key security
  • Static WEP + 802.1x - EAP authentication or static WEP
  • CKIP - Cisco Key Integrity Protocol
  • None + EAP Passthrough - Open Authentication with remote EAP authentication
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the different options for QoS when setting up a WLAN in a Cisco WLC?

A
  • Platinum - Favor Voice
  • Gold - Favor Video
  • Silver - Best Effort (default when creating a WLAN)
  • Bronze - Background
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the Enable Session Timeout setting do in the Advanced section of a Cisco WLC?

A
  • Configures the length of time that a client’s session will last for before it is required to reauthenticate.
  • Default is 1800 seconds (30 mins)
  • Can be completely disabled
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are Wireless Exclusion Policies and what behaviour do they look out for?

A
  • Policies configured on a WLAN that (by default) block clients for 60 seconds as a deterrent to any malicious activity
  • They look out for:
    - Excessive 802.11 association failures
    - Wireless 802.11 authentication failures
    - 802.1x authentication failures
    - Web authentication failures
    - IP address theft or reuse
17
Q

True or False. By default, management access is allowed from WLANs.

A

False. The only way to gain management access is via the wired interfaces. This can be changed by going to the Management tab of the WLC and enabling ‘Enable Controller Management to be accessible from Wireless Clients’.

18
Q

What is DHCP option 43 used for?

A
  • Option 43 can be used to provide vendor specific information to DHCP clients.
  • In a wireless setup, it can be used to tell the APs what IP address their WLC is at. This is useful if the APs are in a different subnet to the WLC.
19
Q

True or False. It is good practice to set the switchports that connect to the APs as access for the management VLAN.

A

True.

20
Q

When logged into the terminal of a WLC, what does autoinstall do?

A

Allows you to automatically download the config of a WLC from a TFTP server.

21
Q

When logged into the terminal of a WLC, what is the Virtual Gateway IP Address?

A

The address used when the WLC communicates directly with wireless clients (e.g. when relaying DHCP requests)

22
Q

When logged into the terminal of a WLC, what is the Multicast IP address?

A

The address used when forwarding traffic to all APs.

23
Q

True or False. When configuring a WLC via the terminal, the regulatory domain must match that of the APs connecting to it.

A

True. This can be found in the model name of the AP. It will be formatted as XXX-XXXXXXXX-<regulatorydomain>-XX.</regulatorydomain>

If the regulatory domain says ‘E’ this means Europe. You can configure it in the WLC as any European country.

24
Q

In the context of a WLC, what is the difference between an interface and a port?

A

An interface is logical, whereas a port is physical.

25
Q

In WLC configuration, what needs to be configured in order to allow a WLAN to work with a physical VLAN?

A
  • An Interface under the Controller > Interfaces menu with the relevant IP information
  • A WLAN under the WLANs menu linked to the relevant interface
26
Q

In WLC configuration, what does Web Policy under WLANs > Security > Layer 3 do?

A
  • Means that even if the user is allowed to authenticate and associate with an AP, they will also receive a web based authentication request. These can be set as:
  • Authentication - When a client attempts to access a web page, they will need to enter a username and password.
  • Passthrough - When a client attempts to access a web page, they don’t need to enter a username and password, however, a warning is displayed and the user just has to accept in order to gain access.
  • Conditional Web Redirect or Splash Page Web Redirect - Require 802.1x authentication.
27
Q

True or False. If you create a WLC ACL, this is enabled by default.

A

False. Once the ACL is created under Access Control Lists, you need to got to Access Control Lists > CPU Access Control Lists, enable ‘Enable CPU ACL’, and select the ACL you want to take effect. These only affect access to the WLC for management purposes.

28
Q

In WLC configuration, what are the different types of WLAN you can setup when first creating a WLAN?

A
  • Normal - A WLAN which people in your company who work for your company will connect to.
  • Guest - A WLAN which guests in your company will connect to.
  • Remote - A WLAN for wired ports on the WLC. Wired clients can also be authenticated by the WLC.
29
Q

List 802.11 Management frames

A
  • Beacons
  • Probe request and response
  • Association request and response
  • Authentication request and response
  • Deauth
  • Reassociation request and response
  • Announcement traffic
30
Q

What interfaces is available while a WLC is booting?

A

Service port interface