nerdexam
Cisco

300-430 · Question #291

An engineer configured a single WLAN with WPA2 Enterprise and wants to use Cisco ISE to implement AVC profiles for users in different departments. Each department is placed into its own unique VLAN…

The correct answer is C. AAA Override. AAA Override must be enabled on the Cisco WLC to allow the controller to accept and apply per-user RADIUS attributes - such as VLAN ID and AVC profile name - returned by Cisco ISE in the Access-Accept message.

Wireless Security and Mobility

Question

An engineer configured a single WLAN with WPA2 Enterprise and wants to use Cisco ISE to implement AVC profiles for users in different departments. Each department is placed into its own unique VLAN and is assigned to an AVC profile, after successfully authenticating to the wireless network. Which feature on the Cisco WLC must be enabled?

Options

  • ALocal Profiling
  • Brole-based access control
  • CAAA Override
  • DChange of Authorization

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    84% (27)
  • D
    6% (2)

Why each option

AAA Override must be enabled on the Cisco WLC to allow the controller to accept and apply per-user RADIUS attributes - such as VLAN ID and AVC profile name - returned by Cisco ISE in the Access-Accept message.

ALocal Profiling

Local Profiling classifies client device types using DHCP or HTTP fingerprinting for local policy enforcement and does not process or apply AVC profiles or VLAN assignments returned by an external RADIUS server.

Brole-based access control

Role-based access control on the WLC enforces policies based on locally defined client roles and does not enable the controller to accept or apply dynamically assigned attributes from ISE during authentication.

CAAA OverrideCorrect

AAA Override instructs the WLC to honor RADIUS vendor-specific attributes (VSAs) and standard attributes returned by ISE during 802.1X authentication, including dynamic VLAN assignment and AVC profile names, overriding the WLAN's static defaults on a per-session basis.

DChange of Authorization

Change of Authorization allows ISE to modify the policy of an already-authenticated session mid-session, but it is not the mechanism that enables the WLC to initially accept and apply RADIUS attributes at the time of authentication.

Concept tested: AAA Override for ISE-driven dynamic VLAN and AVC profile assignment

Source: https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112589-aaa-override-wlc-00.html

Topics

#AAA Override#AVC profiles#VLAN assignment#Cisco ISE

Community Discussion

No community discussion yet for this question.

Full 300-430 Practice