nerdexam
Cisco

300-430 · Question #298

An SSID is set up with central web authentication using Cisco ISE. The new SSID uses guest tunneling from the foreign controller to the anchor controller. Which device must be configured on ISE as…

The correct answer is C. anchor controller. In a foreign-to-anchor guest tunneling topology with central web authentication, the anchor controller owns the client session and is the device that communicates with ISE for RADIUS authentication.

Wireless Security and Mobility

Question

An SSID is set up with central web authentication using Cisco ISE. The new SSID uses guest tunneling from the foreign controller to the anchor controller. Which device must be configured on ISE as the one performing the RADIUS authentication requests for the web authentication method?

Options

  • Aforeign controller
  • Bauthentication server
  • Canchor controller
  • DAPs

How the community answered

(39 responses)
  • A
    13% (5)
  • B
    8% (3)
  • C
    77% (30)
  • D
    3% (1)

Why each option

In a foreign-to-anchor guest tunneling topology with central web authentication, the anchor controller owns the client session and is the device that communicates with ISE for RADIUS authentication.

Aforeign controller

The foreign controller handles only 802.11 association and CAPWAP control; once the client is tunneled to the anchor, the foreign controller plays no role in L3 authentication and does not send RADIUS requests to ISE.

Bauthentication server

The authentication server (ISE) is the RADIUS server that receives and processes authentication requests - it is the destination of RADIUS traffic, not the originating device making requests.

Canchor controllerCorrect

In a guest tunneling architecture, all client traffic is tunneled from the foreign controller to the anchor controller via a mobility EoIP tunnel; the anchor controller terminates client sessions, performs the L3 web authentication redirect, and sends RADIUS Access-Request messages to ISE - therefore ISE must have the anchor controller configured as the Network Access Device (NAD/AAA client), not the foreign controller.

DAPs

APs operate at Layer 2 in a CAPWAP split-MAC architecture and have no visibility into L3 web authentication flows; they never initiate RADIUS requests and are never registered as AAA clients in ISE.

Concept tested: Central web authentication NAD registration with anchor controller

Source: https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113600-cwa-on-wlc.html

Topics

#central web authentication#guest tunneling#anchor controller#RADIUS

Community Discussion

No community discussion yet for this question.

Full 300-430 Practice