Guest-to-staff deny ACLs protect a civic WLAN. How should those ACLs also support operations beyond silent blocking?
Select an answer to reveal the explanation.
Short Explanation
Denies are better when they also talk. Log guest-to-staff ACL hits into monitoring so someone sees the probes. Silent deletes or sticky notes are not visibility.
Full Explanation
ACLs enforce WLAN-originated restrictions and can provide visibility when deny hits are logged into monitoring or SIEM workflows. Logging denied guest-to-staff attempts helps municipal teams detect misuse or misconfiguration. Suppressing logs, relying on informal notes, or periodically permitting the denied path undermines both enforcement and detection.