300-715 · Question #324
Guest users report repeated prompts to authenticate with the portal when connecting to a wireless network. An administrator must configure Cisco ISE to reduce the number of prompts. The solution…
The correct answer is D. Configure an authentication rule for MAC Authentication Bypass users to add an authenticated. To prevent returning guest users from being prompted to authenticate again, configure an authentication rule for MAC Authentication Bypass (MAB) users. This rule allows Cisco ISE to recognize previously authenticated MAC addresses and bypass the portal redirection.
Question
Guest users report repeated prompts to authenticate with the portal when connecting to a wireless network. An administrator must configure Cisco ISE to reduce the number of prompts. The solution must meet the requirements:
- Users must be authenticated once.
- When reconnecting to the visitor network, users do not need to be
redirected to the login page. Which action completes the configuration?
Options
- AConfigure an authorization profile to send a redirection access control list only for unauthenticated
- BConfigure the Wi-Fi Guest Access policy to allow the GuestEndpoint group.
- CConfigure an authorization rule for guest flow to bypass authenticated MAC address.
- DConfigure an authentication rule for MAC Authentication Bypass users to add an authenticated
How the community answered
(49 responses)- A8% (4)
- B2% (1)
- C4% (2)
- D86% (42)
Why each option
To prevent returning guest users from being prompted to authenticate again, configure an authentication rule for MAC Authentication Bypass (MAB) users. This rule allows Cisco ISE to recognize previously authenticated MAC addresses and bypass the portal redirection.
Configuring an authorization profile to send a redirection ACL only for unauthenticated users is a standard part of the initial guest flow but does not address preventing repeated prompts for *returning* authenticated users.
Configuring the Wi-Fi Guest Access policy to allow the GuestEndpoint group is an authorization step and does not, on its own, prevent returning users from being redirected to the login page during the authentication phase.
Configuring an authorization rule for guest flow to bypass authenticated MAC addresses is an authorization step, but the initial prevention of redirection happens at the authentication stage via MAB.
Configuring an authentication rule for MAC Authentication Bypass (MAB) users is crucial. This allows Cisco ISE to perform a MAC address lookup, identify previously authenticated guest devices (e.g., in the GuestEndpoint group), and bypass the redirection to the login page for returning users, ensuring they are authenticated once.
Concept tested: Cisco ISE guest portal bypass with MAB
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_3_1/b_ISE_admin_3_1_chapter_0101.html#ID_224
Topics
Community Discussion
No community discussion yet for this question.