nerdexam
Cisco

300-715 · Question #172

An administrator is configuring RADIUS on a Cisco switch with a key set to Cisc403012128 but is receiving the error "Authentication failed: 22040 Wrong password or invalid shared secret.". What must…

The correct answer is D. Validate that the key is correct on both the Cisco switch as well as Cisco ISE. The error 'Authentication failed: 22040 Wrong password or invalid shared secret' indicates a mismatch in the RADIUS shared secret. To resolve this, the administrator must ensure the shared secret is identical on both the Cisco switch and Cisco ISE.

Network Access Device Administration

Question

An administrator is configuring RADIUS on a Cisco switch with a key set to Cisc403012128 but is receiving the error "Authentication failed: 22040 Wrong password or invalid shared secret.". What must be done to address this issue?

Options

  • AAdd the network device as a NAD inside Cisco ISE using the existing key.
  • BConfigure the key on the Cisco ISE instead of the Cisco switch.
  • CUse a key that is between eight and ten characters.
  • DValidate that the key is correct on both the Cisco switch as well as Cisco ISE.

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    18% (7)
  • C
    3% (1)
  • D
    73% (29)

Why each option

The error 'Authentication failed: 22040 Wrong password or invalid shared secret' indicates a mismatch in the RADIUS shared secret. To resolve this, the administrator must ensure the shared secret is identical on both the Cisco switch and Cisco ISE.

AAdd the network device as a NAD inside Cisco ISE using the existing key.

The question implies the administrator is configuring RADIUS, which includes setting up the Network Access Device (NAD) on ISE. The error points specifically to the key's value, not the absence of the NAD configuration.

BConfigure the key on the Cisco ISE instead of the Cisco switch.

The RADIUS shared secret must be configured identically on *both* the Cisco switch (client) and Cisco ISE (server) to establish secure communication. Configuring it only on one device would prevent authentication.

CUse a key that is between eight and ten characters.

While strong password policies recommend longer and more complex keys, the error message indicates a mismatch or invalidity of the *current* key, not a failure due to length constraints. RADIUS shared secrets do not inherently have an 8-10 character requirement, though strong practices dictate longer, more complex secrets.

DValidate that the key is correct on both the Cisco switch as well as Cisco ISE.Correct

The shared secret is a pre-shared key used for securing communication between the RADIUS client (Cisco switch) and the RADIUS server (Cisco ISE). If this key is not identical on both devices, RADIUS authentication packets cannot be correctly encrypted or decrypted, leading directly to the 'Wrong password or invalid shared secret' error and preventing successful communication.

Concept tested: RADIUS Shared Secret Configuration

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ISE_admin_guide_27/b_ISE_admin_guide_27_chapter_01000.html#concept_AEFDF7A1E14E40E3A0E5C9CC9CC5A162

Topics

#RADIUS Shared Secret#NAD Configuration#Cisco ISE Troubleshooting

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice