A remote branch must connect its AP/controller WLAN path across the public Internet back to headquarters. Which protection best fits that untrusted WAN transit?
Select an answer to reveal the explanation.
Short Explanation
Internet between branch APs and HQ is hostile territory. Wrap that AP/controller path in IPsec. Guest PSKs and cleartext CAPWAP are not WAN crypto for infrastructure.
Full Explanation
Encrypting WLAN infrastructure control and data tunnels with IPsec protects branch AP/controller paths that traverse the untrusted Internet. Cleartext tunneling, guest PSKs, or public advertisement of management networks do not adequately protect municipal branch WLAN infrastructure in transit.