300-715 · Question #366
Refer to the exhibit. An engineer must configure central web authentication on the Cisco Wireless LAN Controller to use Cisco ISE for all guests connected to the wireless network. The Cisco Wireless…
The correct answer is D. TCP 8443. For Central Web Authentication (CWA), after the WLC sends a RADIUS request to ISE and receives a redirect URL in the Access-Accept response, the WLC redirects the guest user's browser to the ISE Guest portal. This portal is hosted on ISE over TCP 8443 (HTTPS). The firewall must…
Question
Refer to the exhibit. An engineer must configure central web authentication on the Cisco Wireless LAN Controller to use Cisco ISE for all guests connected to the wireless network. The Cisco Wireless LAN Controller and the Cisco ISE were configured, and the RADIUS-related ports were opened on the firewall. Which additional port must be opened to allow communication between the Cisco Wireless LAN Controller and Cisco ISE?
Options
- ATCP 80
- BUDP 1645
- CUDP 1813
- DTCP 8443
How the community answered
(24 responses)- A4% (1)
- C4% (1)
- D92% (22)
Explanation
For Central Web Authentication (CWA), after the WLC sends a RADIUS request to ISE and receives a redirect URL in the Access-Accept response, the WLC redirects the guest user's browser to the ISE Guest portal. This portal is hosted on ISE over TCP 8443 (HTTPS). The firewall must allow TCP 8443 between the WLC (or more precisely, between the client and ISE) for the guest login page to load correctly. The RADIUS-related ports (UDP 1645/1812 for authentication and UDP 1813/1646 for accounting) are already opened as stated in the question. TCP 80 (A) is standard HTTP and not used for the secure ISE portal. This makes TCP 8443 (D) the additional port required specifically for the web redirection component of CWA.
Topics
Community Discussion
No community discussion yet for this question.