300-715 · Question #117
When creating a policy within Cisco ISE for network access control, the administrator wants to allow different access restrictions based upon the wireless SSID to which the device is connecting…
The correct answer is C. Radius Called-Station-ID CONTAINS <SSID Name>. To allow different access restrictions based on the wireless SSID a device connects to in Cisco ISE, the administrator must use the Radius Called-Station-ID policy condition.
Question
When creating a policy within Cisco ISE for network access control, the administrator wants to allow different access restrictions based upon the wireless SSID to which the device is connecting. Which policy condition must be used in order to accomplish this?
Options
- ANetwork Access NetworkDeviceName CONTAINS <SSID Name>
- BDEVICE Device Type CONTAINS <SSID Name>
- CRadius Called-Station-ID CONTAINS <SSID Name>
- DAirespace Airespace-Wlan-ld CONTAINS <SSID Name>
How the community answered
(35 responses)- A3% (1)
- B6% (2)
- C89% (31)
- D3% (1)
Why each option
To allow different access restrictions based on the wireless SSID a device connects to in Cisco ISE, the administrator must use the Radius Called-Station-ID policy condition.
Network Access NetworkDeviceName refers to the name of the access device itself (e.g., the WLC), not the SSID the client is connecting to.
DEVICE Device Type refers to the type of end-device (e.g., iPhone, Windows PC), not the SSID it is connecting to.
The Radius Called-Station-ID attribute is typically sent by the Network Access Device (NAD), such as a WLC, and contains information including the SSID to which the device is connecting. Using this attribute in an ISE policy allows for granular control and different authorization outcomes based on the specific wireless network (SSID) being used for access.
Airespace Airespace-Wlan-Id is a Cisco proprietary attribute that might contain the WLAN ID, but Called-Station-ID is a standard RADIUS attribute that typically includes the SSID name and is more commonly used and reliably available for this purpose.
Concept tested: Cisco ISE Policy - SSID-based Access Control
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_guide_3_0/b_ise_admin_guide_30_chapter_0100.html#concept_BB02B41CF81845A987D6B42978A326ED
Topics
Community Discussion
No community discussion yet for this question.