300-715 · Question #277
A network engineer is attempting to terminate and reinitialize wireless user sessions individually by using the Live Sessions tab in Cisco ISE. Cisco ISE and the Cisco WLC are separated by a…
The correct answer is C. UDP port 1700. To enable Cisco ISE to terminate and reinitialize wireless user sessions via the Live Sessions tab, UDP port 1700 must be opened on the firewall between ISE and the Wireless LAN Controller (WLC).
Question
A network engineer is attempting to terminate and reinitialize wireless user sessions individually by using the Live Sessions tab in Cisco ISE. Cisco ISE and the Cisco WLC are separated by a firewall. Which port must be allowed on the firewall so that the network engineer can perform this function from Cisco ISE?
Options
- ATCP port 8443
- BUDP port 5246
- CUDP port 1700
- DTCP port 3791
How the community answered
(38 responses)- A5% (2)
- B3% (1)
- C92% (35)
Why each option
To enable Cisco ISE to terminate and reinitialize wireless user sessions via the Live Sessions tab, UDP port 1700 must be opened on the firewall between ISE and the Wireless LAN Controller (WLC).
TCP port 8443 is used for Cisco ISE's web-based portals (e.g., guest portal) and administration UI, not for CoA communication with NADs.
UDP port 5246 is used by the Cisco TrustSec Security Group Tag Exchange Protocol (SXP) for SGT propagation, not for CoA.
When using the Live Sessions tab in Cisco ISE to terminate or reinitialize a user session, Cisco ISE sends a Change of Authorization (CoA) message to the Network Access Device (NAD), which in this case is the Cisco WLC. CoA messages are sent over RADIUS, specifically using UDP port 1700. Therefore, this port must be open on any firewall between ISE and the WLC.
TCP port 3791 is used for RADIUS accounting messages, but the primary port for CoA is UDP 1700.
Concept tested: Cisco ISE Change of Authorization (CoA) port
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_3_0_chapter_011.html
Topics
Community Discussion
No community discussion yet for this question.