nerdexam
Cisco

300-430 · Question #253

Refer to the exhibit. The redirect ACL is configured on Cisco Catalyst 9800-40 WLC version 17.3.3. The ACL is pushed by Cisco ISE version 3 for a CWA SSID implementation. The IP address 10.48.39 28…

The correct answer is A. on a new or existing authorization profile as cisco-av-pair for URL redirect under policy elements. For Central Web Authentication on the 9800 WLC, the redirect ACL configured on the WLC must be referenced by name in an ISE authorization profile using the cisco-av-pair attribute so ISE can push it to the WLC upon client authentication.

Security for Wireless Client Connectivity

Question

Refer to the exhibit. The redirect ACL is configured on Cisco Catalyst 9800-40 WLC version 17.3.3. The ACL is pushed by Cisco ISE version 3 for a CWA SSID implementation. The IP address 10.48.39 28 represents the ISE IP address. Where must the ACL be applied?

Exhibit

300-430 question #253 exhibit

Options

  • Aon a new or existing authorization profile as cisco-av-pair for URL redirect under policy elements
  • Bon a new or existing cisco-av-pair dictionary under policy elements for URL redirect
  • Con a new allowed protocol under authentication profile under policy elements for URL redirect
  • Don an existing cisco-av-pair library condition under policy elements for URL redirect

How the community answered

(37 responses)
  • A
    59% (22)
  • B
    19% (7)
  • C
    8% (3)
  • D
    14% (5)

Why each option

For Central Web Authentication on the 9800 WLC, the redirect ACL configured on the WLC must be referenced by name in an ISE authorization profile using the cisco-av-pair attribute so ISE can push it to the WLC upon client authentication.

Aon a new or existing authorization profile as cisco-av-pair for URL redirect under policy elementsCorrect

An ISE authorization profile under Policy Elements is where the URL redirect and URL-redirect-acl cisco-av-pair values are configured for CWA. When a client authenticates, ISE evaluates the authorization policy and returns the authorization profile containing both the redirect URL and the ACL name - the 9800 WLC uses the ACL name to identify which locally configured ACL defines redirect and permit traffic behavior for the pre-authenticated client.

Bon a new or existing cisco-av-pair dictionary under policy elements for URL redirect

The cisco-av-pair dictionary under policy elements is a condition component used to match attributes in policy rules, not a place to configure authorization result attributes like URL redirect.

Con a new allowed protocol under authentication profile under policy elements for URL redirect

Allowed protocols under authentication profiles define which EAP and non-EAP protocols are permitted during authentication negotiation and have no function related to URL redirect ACL assignment.

Don an existing cisco-av-pair library condition under policy elements for URL redirect

A cisco-av-pair library condition is used to build matching logic in policy set conditions, not to assign URL redirect attributes as part of an authorization result.

Concept tested: ISE CWA authorization profile redirect ACL cisco-av-pair configuration

Source: https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215855-configure-central-web-authentication-on.html

Topics

#CWA#ISE redirect ACL#authorization profile#Catalyst 9800

Community Discussion

No community discussion yet for this question.

Full 300-430 Practice