300-710 · Question #154
An organization is using a Cisco FTD and Cisco ISE to perform identity-based access controls. A network administrator is analyzing the Cisco FTD events and notices that unknown user traffic is being…
The correct answer is C. Add the unknown user in the Access Control Policy in Cisco FTD. When Cisco FTD and Cisco ISE are integrated for identity-based access control, traffic from unauthenticated or unrecognized sessions is tagged with the identity 'Unknown.' By default, there may be no explicit Access Control Policy (ACP) rule blocking this identity, so the…
Question
An organization is using a Cisco FTD and Cisco ISE to perform identity-based access controls. A network administrator is analyzing the Cisco FTD events and notices that unknown user traffic is being allowed through the firewall. How should this be addressed to block the traffic while allowing legitimate user traffic?
Options
- AModify lhe Cisco ISE authorization policy to deny this access to the user.
- BModify Cisco ISE to send only legitimate usernames to the Cisco FTD.
- CAdd the unknown user in the Access Control Policy in Cisco FTD.
- DAdd the unknown user in the Malware & File Policy in Cisco FTD.
How the community answered
(65 responses)- A6% (4)
- B5% (3)
- C75% (49)
- D14% (9)
Explanation
When Cisco FTD and Cisco ISE are integrated for identity-based access control, traffic from unauthenticated or unrecognized sessions is tagged with the identity 'Unknown.' By default, there may be no explicit Access Control Policy (ACP) rule blocking this identity, so the traffic falls through to a permissive default action. The correct fix is to add an explicit ACP rule in Cisco FTD that matches the 'Unknown' user identity and sets the action to Block. This ensures unknown/unauthenticated traffic is denied while authenticated user traffic continues to match the appropriate identity-based rules and is allowed. Option A (ISE authorization policy) controls network access at the ISE level but does not directly fix FTD's handling of already-passed traffic. Option B is not operationally practical. Option D (Malware & File Policy) addresses file inspection, not identity-based access.
Topics
Community Discussion
No community discussion yet for this question.