Cisco Certified Network Associate (CCNA) 200-301 · Free study guide
Objective 2.7 — Map WLAN infrastructure connections
A WLAN depends on wired connections that carry AP management, controller control, and client segments. Draw the physical cable first, then annotate what logical traffic crosses it.
AP switch connections
An AP commonly connects to a PoE-capable access switchport. In a centralized tunneling design, the AP may need one management VLAN on an access port while client traffic is carried inside a tunnel to the controller. Other designs can locally switch client VLANs and may require trunk behavior at the AP port. The architecture decides; do not memorize one switchport mode for every AP.
Verify PoE delivery, link speed, access or trunk mode, management addressing, gateway, DNS where discovery uses it, and reachability to the manager.
Controller connections
A controller commonly needs an 802.1Q trunk toward the switching infrastructure so management and mapped client VLANs can reach it. The switch's allowed list, native choice, and controller interface mappings must agree. A missing client VLAN can let APs join and SSIDs appear while users fail after association.
Controllers may aggregate physical links into a LAG. The upstream switch must provide a compatible port-channel design. Treat the aggregate as one logical trunk and verify every member.
Logical mappings
An SSID or WLAN profile maps through policy to a client VLAN or interface. The management VLAN serves infrastructure identity; it should not be confused with every client segment. Guest, corporate, and voice WLANs can share AP radios while entering different wired VLANs and policy paths.
Map: client → SSID → policy/interface → VLAN → trunk → gateway. This chain is more useful than looking at a broadcast name alone.
Worked scenario
APs join the controller and advertise CORP, but clients receive no address. The controller's CORP interface maps to VLAN 30. The controller uplink trunk allows VLANs 10 and 20 only. Add VLAN 30 under approved change control and verify it reaches the DHCP relay or server path. Rebooting APs would not repair the wired omission.
Verification evidence
Inspect AP power and join state, switchport operational mode, controller LAG, trunk allowance, WLAN-to-interface mapping, VLAN gateway, DHCP path, and client association details. Use counters or a capture to find the first point where the expected client flow disappears.
Common traps
- Assuming every AP port must be a trunk.
- Treating AP join success as proof client VLANs work.
- Mixing management and client VLAN roles.
- Configuring LAG on only one side.
- Troubleshooting RF before tracing the wired client path.
Readiness checklist
- I can draw AP and controller physical links.
- I can map an SSID to a wired client VLAN.
- I understand when access, trunk, and LAG roles appear.
- I verify PoE, control, and data paths independently.
Practice and apply this objective
A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.
Start practicing free