A municipal guest VLAN must reach the Internet but must not talk to staff servers. Where should ACLs primarily enforce that Internet-only restriction?
Select an answer to reveal the explanation.
Short Explanation
Internet-only guests need wired ACLs where that VLAN hits the campus. Distribution-layer ACLs block staff destinations while allowing egress. Renaming SSIDs or dimming RF is not access control.
Full Explanation
Access control lists on the distribution layer (or equivalent wired enforcement points) restrict guest VLAN traffic to Internet-only destinations and deny paths into staff networks. For municipal guest WLAN segments, that wired ACL placement is the durable control once wireless association succeeds. Cosmetic SSID changes, client bookmarks, or RF power tweaks do not enforce destination policy.