300-365 · Question #9
CMX Facebook WiFi can allow access to the network before authentication. Which two of the following options are available? (Choose two)
The correct answer is B. Allow HTTP traffic only before authentication and block all the traffic. D. Allow all the traffic before authentication and intercept HTTP only. CMX Facebook WiFi offers two pre-authentication traffic handling modes that control what clients can access before completing Facebook-based captive portal authentication.
Question
CMX Facebook WiFi can allow access to the network before authentication. Which two of the following options are available? (Choose two)
Options
- AAllow all the traffic before authentication and intercept HTTPs only.
- BAllow HTTP traffic only before authentication and block all the traffic.
- CAllow SNMP traffic only before authentication and block all the traffic.
- DAllow all the traffic before authentication and intercept HTTP only.
- EAllow HTTPs traffic only before authentication and block all other traffic.
How the community answered
(39 responses)- A5% (2)
- B92% (36)
- C3% (1)
Why each option
CMX Facebook WiFi offers two pre-authentication traffic handling modes that control what clients can access before completing Facebook-based captive portal authentication.
CMX Facebook WiFi does not offer an option to intercept HTTPS traffic only before authentication, as HTTPS interception would require certificate substitution and is not a valid pre-auth mode in CMX.
Allowing only HTTP traffic before authentication ensures the captive portal redirect mechanism works for unauthenticated clients while blocking all other protocols, preventing unauthenticated network access beyond what is needed to trigger the login portal.
SNMP is a network management protocol and has no role in pre-authentication traffic control for a guest captive portal solution like CMX Facebook WiFi.
Allowing all traffic before authentication but intercepting only HTTP requests enables a permissive pre-auth experience where the Facebook login page is presented when clients attempt HTTP browsing, while non-HTTP traffic passes freely.
Allowing only HTTPS traffic before authentication is not a supported pre-authentication mode in CMX Facebook WiFi; the portal redirect relies on HTTP, not HTTPS.
Concept tested: CMX Facebook WiFi pre-authentication traffic modes
Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/facebook_wifi.html
Topics
Community Discussion
No community discussion yet for this question.