nerdexam
Cisco

300-715 · Question #315

An engineer must create an authentication policy in Cisco ISE to allow wired printers that lack support for 802.1X onto the network. What must the RadiusFlowType be set to in the policy to meet the re

The correct answer is B. Wired_MAB. To allow wired printers without 802.1X support onto the network, the authentication policy's RadiusFlowType must be configured as Wired_MAB (MAC Authentication Bypass).

Policy Enforcement

Question

An engineer must create an authentication policy in Cisco ISE to allow wired printers that lack support for 802.1X onto the network. What must the RadiusFlowType be set to in the policy to meet the requirement?

Options

  • AMAB
  • BWired_MAB
  • CCompliant_Devices
  • DCompliance_Unknown_Devices

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    93% (25)
  • D
    4% (1)

Why each option

To allow wired printers without 802.1X support onto the network, the authentication policy's RadiusFlowType must be configured as Wired_MAB (MAC Authentication Bypass).

AMAB

MAB is a general term; in Cisco ISE, specific RadiusFlowTypes like Wired_MAB or Wireless_MAB are used to distinguish the access type.

BWired_MABCorrect

Wired_MAB (MAC Authentication Bypass) is the correct RadiusFlowType for authenticating wired devices that do not support 802.1X, such as printers, by using their MAC address as the credential. This allows these non-802.1X-capable devices to gain network access based on their MAC address being known and authorized in Cisco ISE.

CCompliant_Devices

Compliant_Devices is a condition typically used in authorization policies after a device has successfully authenticated and undergone posture assessment, not for the initial authentication method.

DCompliance_Unknown_Devices

Compliance_Unknown_Devices is also a condition for authorization policies, indicating devices whose compliance status is unknown, not an authentication method.

Concept tested: Cisco ISE Wired MAC Authentication Bypass (MAB)

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_3_0/b_ise_admin_3_0_chapter_01000.html#concept_CDCE26214B8C461AA4533038C40292B2

Topics

#MAB#Wired Authentication#Authentication Policy#Non-802.1X

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice