300-715 · Question #315
An engineer must create an authentication policy in Cisco ISE to allow wired printers that lack support for 802.1X onto the network. What must the RadiusFlowType be set to in the policy to meet the re
The correct answer is B. Wired_MAB. To allow wired printers without 802.1X support onto the network, the authentication policy's RadiusFlowType must be configured as Wired_MAB (MAC Authentication Bypass).
Question
An engineer must create an authentication policy in Cisco ISE to allow wired printers that lack support for 802.1X onto the network. What must the RadiusFlowType be set to in the policy to meet the requirement?
Options
- AMAB
- BWired_MAB
- CCompliant_Devices
- DCompliance_Unknown_Devices
How the community answered
(27 responses)- A4% (1)
- B93% (25)
- D4% (1)
Why each option
To allow wired printers without 802.1X support onto the network, the authentication policy's RadiusFlowType must be configured as Wired_MAB (MAC Authentication Bypass).
MAB is a general term; in Cisco ISE, specific RadiusFlowTypes like Wired_MAB or Wireless_MAB are used to distinguish the access type.
Wired_MAB (MAC Authentication Bypass) is the correct RadiusFlowType for authenticating wired devices that do not support 802.1X, such as printers, by using their MAC address as the credential. This allows these non-802.1X-capable devices to gain network access based on their MAC address being known and authorized in Cisco ISE.
Compliant_Devices is a condition typically used in authorization policies after a device has successfully authenticated and undergone posture assessment, not for the initial authentication method.
Compliance_Unknown_Devices is also a condition for authorization policies, indicating devices whose compliance status is unknown, not an authentication method.
Concept tested: Cisco ISE Wired MAC Authentication Bypass (MAB)
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_3_0/b_ise_admin_3_0_chapter_01000.html#concept_CDCE26214B8C461AA4533038C40292B2
Topics
Community Discussion
No community discussion yet for this question.