300-715 · Question #383
A network engineer must define a Redirect ACL on a Cisco Wireless LAN Controller. The ACL must force unknown users to authenticate via a captive portal located on a Cisco ISE PSN on another network se
The correct answer is B. TCP port 8443. When a Cisco Wireless LAN Controller (WLC) redirects unauthenticated users to a captive portal hosted on a Cisco ISE PSN for Central Web Authentication (CWA), the portal is served over HTTPS on TCP port 8443. This is the default port for ISE guest and sponsor portals. The firewal
Question
A network engineer must define a Redirect ACL on a Cisco Wireless LAN Controller. The ACL must force unknown users to authenticate via a captive portal located on a Cisco ISE PSN on another network segment separated by a firewall. Which port must be permitted in the firewall to allow traffic between the Cisco Wireless LAN Controller and Cisco ISE?
Options
- AUDP port 1812
- BTCP port 8443
- CUDP port 1645
- DTCP port 8445
How the community answered
(31 responses)- B94% (29)
- C3% (1)
- D3% (1)
Explanation
When a Cisco Wireless LAN Controller (WLC) redirects unauthenticated users to a captive portal hosted on a Cisco ISE PSN for Central Web Authentication (CWA), the portal is served over HTTPS on TCP port 8443. This is the default port for ISE guest and sponsor portals. The firewall between the WLC and the ISE PSN must permit TCP port 8443 inbound to allow clients' browsers to reach the ISE web portal. UDP port 1812 is used for RADIUS authentication between the WLC and ISE, UDP port 1645 is the legacy RADIUS authentication port, and TCP port 8445 is associated with ISE administrative or sponsor portal access. For the captive portal redirect to function correctly, TCP 8443 must be open through the firewall.
Topics
Community Discussion
No community discussion yet for this question.