nerdexam
Cisco

300-715 · Question #326

A network security administrator needs a web authentication configuration when a guest user connects to the network with a wireless connection using these steps: - An initial MAB request is sent to…

The correct answer is C. NAD with central WebAuth. The described scenario, where a WLC performs initial MAB and redirects unknown users to a portal on Cisco ISE for AUP acceptance, aligns with Central Web Authentication. The administrator must configure NAD with central WebAuth on Cisco ISE.

Web Auth and Guest Services

Question

A network security administrator needs a web authentication configuration when a guest user connects to the network with a wireless connection using these steps:

  • An initial MAB request is sent to the Cisco ISE node.
  • Cisco ISE responds with a URL redirection authorization profile if

the user's MAC address is unknown in the endpoint identity store.

  • The URL redirection presents the user with an AUP acceptance page

when the user attempts to go to any URL. Which authentication must the administrator configure on Cisco ISE?

Options

  • Awired NAD with local WebAuth
  • BWLC with local WebAuth
  • CNAD with central WebAuth
  • Ddevice registration WebAuth

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    78% (31)
  • D
    13% (5)

Why each option

The described scenario, where a WLC performs initial MAB and redirects unknown users to a portal on Cisco ISE for AUP acceptance, aligns with Central Web Authentication. The administrator must configure NAD with central WebAuth on Cisco ISE.

Awired NAD with local WebAuth

Wired NAD with local WebAuth implies the web authentication portal is hosted on the wired NAD itself, which contradicts ISE performing the redirection.

BWLC with local WebAuth

WLC with local WebAuth implies the web authentication portal is hosted on the WLC, which is not the case when ISE sends a URL redirection to its own portal.

CNAD with central WebAuthCorrect

This scenario precisely describes Central Web Authentication (CWA), where the Network Access Device (NAD), such as a Wireless LAN Controller (WLC), sends an MAB request, and Cisco ISE, upon identifying an unknown MAC address, responds with a URL redirection. The user is then redirected to a web portal hosted on Cisco ISE for AUP acceptance or authentication, making it a central web authentication flow.

Ddevice registration WebAuth

Device registration WebAuth is a specific type of web authentication for registering devices, not the general guest AUP acceptance flow described.

Concept tested: Cisco ISE Central Web Authentication (CWA)

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_3_1/b_ISE_admin_3_1_chapter_0101.html#ID_447

Topics

#Web Authentication#Guest Access#Cisco ISE#URL Redirection

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice