300-430 · Question #298
An SSID is set up with central web authentication using Cisco ISE. The new SSID uses guest tunneling from the foreign controller to the anchor controller. Which device must be configured on ISE as…
The correct answer is C. anchor controller. In a foreign-to-anchor guest tunneling topology with central web authentication, the anchor controller owns the client session and is the device that communicates with ISE for RADIUS authentication.
Question
An SSID is set up with central web authentication using Cisco ISE. The new SSID uses guest tunneling from the foreign controller to the anchor controller. Which device must be configured on ISE as the one performing the RADIUS authentication requests for the web authentication method?
Options
- Aforeign controller
- Bauthentication server
- Canchor controller
- DAPs
How the community answered
(39 responses)- A13% (5)
- B8% (3)
- C77% (30)
- D3% (1)
Why each option
In a foreign-to-anchor guest tunneling topology with central web authentication, the anchor controller owns the client session and is the device that communicates with ISE for RADIUS authentication.
The foreign controller handles only 802.11 association and CAPWAP control; once the client is tunneled to the anchor, the foreign controller plays no role in L3 authentication and does not send RADIUS requests to ISE.
The authentication server (ISE) is the RADIUS server that receives and processes authentication requests - it is the destination of RADIUS traffic, not the originating device making requests.
In a guest tunneling architecture, all client traffic is tunneled from the foreign controller to the anchor controller via a mobility EoIP tunnel; the anchor controller terminates client sessions, performs the L3 web authentication redirect, and sends RADIUS Access-Request messages to ISE - therefore ISE must have the anchor controller configured as the Network Access Device (NAD/AAA client), not the foreign controller.
APs operate at Layer 2 in a CAPWAP split-MAC architecture and have no visibility into L3 web authentication flows; they never initiate RADIUS requests and are never registered as AAA clients in ISE.
Concept tested: Central web authentication NAD registration with anchor controller
Source: https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113600-cwa-on-wlc.html
Topics
Community Discussion
No community discussion yet for this question.