300-430 · Question #288
An engineer must define credentials for an autonomous access point that is configured to use 802.1X authentication against the switch port is attached to. Where are the credentials defined?
The correct answer is A. RADIUS server. When an autonomous AP acts as an 802.1X supplicant authenticating to a switch port, the RADIUS server is the authentication authority that holds and validates the AP's credentials.
Question
An engineer must define credentials for an autonomous access point that is configured to use 802.1X authentication against the switch port is attached to. Where are the credentials defined?
Options
- ARADIUS server
- BCisco Prime Infrastructure
- Cwireless LAN controller
- DTACACS server
How the community answered
(51 responses)- A94% (48)
- B2% (1)
- D4% (2)
Why each option
When an autonomous AP acts as an 802.1X supplicant authenticating to a switch port, the RADIUS server is the authentication authority that holds and validates the AP's credentials.
In 802.1X port-based authentication, the autonomous AP is the supplicant and the switch is the authenticator; the switch forwards the AP's identity and credentials to the RADIUS server, which is the authentication server that stores the valid credentials and returns an Access-Accept or Access-Reject. The credentials (username/password or certificate) must therefore be defined on the RADIUS server so it can verify the AP's identity and permit the switchport to transition to an authorized state.
Cisco Prime Infrastructure is a network management platform used for monitoring and provisioning; it does not serve as an 802.1X authentication server and does not store supplicant credentials.
A wireless LAN controller manages lightweight APs over CAPWAP and does not function as a RADIUS authentication server for autonomous AP 802.1X supplicant authentication to a switch.
TACACS+ is a device administration protocol used for CLI access control (login, enable, command authorization), not for 802.1X port authentication, so credentials defined there would not be consulted during EAP-based port authentication.
Concept tested: 802.1X supplicant authentication for autonomous APs
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-16/sec-user-8021x-xe-16-book/config-ieee-802x-pba.html
Topics
Community Discussion
No community discussion yet for this question.