nerdexam
Cisco

300-365 · Question #184

You have multiple mDNS profiles defined on a Cisco Wireless LAN Controller for different user roles. Which two RADIUS attributes can be used on the ISE authorization profile to assign different mDNS…

The correct answer is C. Cisco:cisco-av-pair:mDNS-profile-name=PROFILE-NAME D. Radius:Class:mDNS-profile-name=PROFILE-NAME. On a Cisco WLC, ISE authorization profiles can assign mDNS service profiles per user by returning either a Cisco AV pair or a RADIUS Class attribute that carries the mDNS profile name.

Guest Access Deployment

Question

You have multiple mDNS profiles defined on a Cisco Wireless LAN Controller for different user roles. Which two RADIUS attributes can be used on the ISE authorization profile to assign different mDNS profile per user if it has the correct role? (Choose two.)

Options

  • ACisco:cisco-av-pair:userid=USER
  • BRadius:Class: role=ROLE
  • CCisco:cisco-av-pair:mDNS-profile-name=PROFILE-NAME
  • DRadius:Class:mDNS-profile-name=PROFILE-NAME
  • ECisco:cisco-av-pair:role=ROLE

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    77% (24)
  • E
    13% (4)

Why each option

On a Cisco WLC, ISE authorization profiles can assign mDNS service profiles per user by returning either a Cisco AV pair or a RADIUS Class attribute that carries the mDNS profile name.

ACisco:cisco-av-pair:userid=USER

The 'cisco-av-pair:userid=USER' attribute carries user identity information only and is not recognized by the WLC as an mDNS profile assignment directive.

BRadius:Class: role=ROLE

The Class attribute formatted as 'role=ROLE' returns a role value, not an mDNS profile name, so the WLC cannot use it to select a specific mDNS service policy.

CCisco:cisco-av-pair:mDNS-profile-name=PROFILE-NAMECorrect

The Cisco vendor-specific AV pair 'cisco-av-pair:mDNS-profile-name=PROFILE-NAME' is a supported attribute that ISE can return in an authorization profile, which the WLC interprets to apply the named mDNS service policy to that user session.

DRadius:Class:mDNS-profile-name=PROFILE-NAMECorrect

The RADIUS Class attribute with the value 'mDNS-profile-name=PROFILE-NAME' is an alternative supported mechanism for the WLC to receive and apply the correct mDNS profile during user authorization.

ECisco:cisco-av-pair:role=ROLE

The 'cisco-av-pair:role=ROLE' AV pair assigns a user role but does not contain the mDNS profile name field the WLC requires to apply an mDNS service profile.

Concept tested: ISE RADIUS attribute assignment of WLC mDNS profiles

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_17_config_guide/mdns-service-discovery.html

Topics

#mDNS#RADIUS attributes#ISE authorization#Cisco AV pair

Community Discussion

No community discussion yet for this question.

Full 300-365 Practice