hardMultiple Choice
350-401 Practice Question: An engineer is configuring a new Cisco 9800 WLC…
An engineer is configuring a new Cisco 9800 WLC in a branch office. The WLC will manage 50 APs and must provide guest access with a captive portal. The engineer configures a guest SSID with open authentication and a redirect ACL for the captive portal. However, after the configuration, clients can associate to the guest SSID but cannot reach the captive portal page. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that captive portal requires a RADIUS server or a dedicated interface, but the real trap is that the redirect ACL must explicitly permit traffic to the portal server and DNS, or the portal page will never load.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The redirect ACL is missing entries for DNS and HTTP traffic to the captive portal server.
The redirect ACL is used to permit traffic that should bypass the captive portal (e.g., DNS and HTTP traffic to the captive portal server) while redirecting all other HTTP traffic. If the ACL is missing entries for DNS and HTTP to the portal server, the client's DNS lookup for the portal server or the initial HTTP request to it will be redirected instead of allowed, causing the captive portal page to fail to load. This is a common misconfiguration on Cisco 9800 WLCs, where the redirect ACL must explicitly permit the necessary traffic to the portal server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The guest SSID is configured with open authentication, which does not support captive portal.
Why it's wrong here
Open authentication is fully compatible with captive portals on Cisco wireless LAN controllers. With open or 'open + web-auth' SSIDs, clients can associate and obtain an IP address without credentials, and the captive portal then intercepts their unauthenticated HTTP traffic to display the login page. The actual trigger for the portal is the redirect ACL, not the authentication method. Thus, using open authentication is normal practice for guest SSIDs and does not explain why the captive portal fails to appear.
- ✓
The redirect ACL is missing entries for DNS and HTTP traffic to the captive portal server.
Why this is correct
The redirect ACL, also called the pre-auth ACL, is the core mechanism that makes a Cisco WLC captive portal work. Before a client is web-authenticated, this ACL defines which traffic is permitted through, and everything else is redirected to the virtual interface (or portal server). If entries for DNS (UDP/53) and HTTP (TCP/80) toward the captive portal server or the virtual gateway are missing, the client cannot resolve the portal domain or its initial HTTP request is blackholed instead of being redirected. Without those explicit permits, the WLC drops or fails to redirect the client's traffic, so the captive portal never appears in the browser.
- ✗
The WLC does not have a dedicated guest interface configured.
Why it's wrong here
A dedicated guest interface is not a prerequisite for a WLC captive portal. In Cisco WLC design, you can assign the guest SSID to a standard dynamic VLAN interface with its own subnet and DHCP scope; the WLC uses the virtual interface to generate the redirect URL. The absence of a separately named 'guest' interface only means the traffic is not isolated to a dedicated guest VLAN, which is a security concern, not a functional failure. Therefore, lacking a dedicated guest interface would not prevent the captive portal from loading.
- ✗
The captive portal requires a RADIUS server to be configured on the WLC.
Why it's wrong here
RADIUS is optional for captive portal authentication on a Cisco WLC. When you configure a web-auth SSID, you can choose local authentication (username/password stored on the WLC), RADIUS, or an external portal server like a custom web server. The WLC can also present a built-in login page and authenticate locally, so RADIUS is not a required component. Consequently, the absence of a RADIUS server cannot be the reason the captive portal is not being presented.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.