nerdexam
Cisco

300-715 · Question #318

An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which…

The correct answer is D. Renew the expired certificate on one of the PSN. An "EAP-TLS authentication failed" message for a user moving between sites, each with its own PSN, indicates a potential issue with a PSN's certificate. The most likely cause is an expired certificate on one of the PSN nodes.

Policy Enforcement

Question

An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE?

Options

  • AUse a third-party certificate on the network device.
  • BAdd the device to all PSN nodes in the deployment.
  • CConfigure an authorization profile for the end users.
  • DRenew the expired certificate on one of the PSN.

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    17% (6)
  • C
    8% (3)
  • D
    72% (26)

Why each option

An "EAP-TLS authentication failed" message for a user moving between sites, each with its own PSN, indicates a potential issue with a PSN's certificate. The most likely cause is an expired certificate on one of the PSN nodes.

AUse a third-party certificate on the network device.

While using third-party certificates is common, this choice doesn't address the specific symptom of "EAP-TLS authentication failed" likely due to an expired certificate on a PSN, not the type of certificate on the network device.

BAdd the device to all PSN nodes in the deployment.

"Add the device to all PSN nodes" is not a standard configuration step; network devices are typically registered once as NADs in ISE. Endpoints do not need to be added to PSNs.

CConfigure an authorization profile for the end users.

An authorization profile defines what access the user gets after successful authentication, not the cause of an EAP-TLS authentication failure itself.

DRenew the expired certificate on one of the PSN.Correct

EAP-TLS authentication relies heavily on valid server certificates presented by the PSN to the client. If a user moves to a site whose PSN has an expired EAP-TLS certificate, the client will fail to establish a secure TLS tunnel, resulting in an "EAP-TLS authentication failed" message. Renewing the expired certificate on the affected PSN ensures continuous trust and successful authentication across all sites.

Concept tested: Cisco ISE EAP-TLS Certificate Management

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_3_0/b_ise_admin_3_0_chapter_01000.html#concept_56B75775317E4598A843E2C4D350B4CC

Topics

#EAP-TLS#Certificates#Authentication Failure#PSN

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice