nerdexam
Cisco

300-715 · Question #383

A network engineer must define a Redirect ACL on a Cisco Wireless LAN Controller. The ACL must force unknown users to authenticate via a captive portal located on a Cisco ISE PSN on another network se

The correct answer is B. TCP port 8443. When a Cisco Wireless LAN Controller (WLC) redirects unauthenticated users to a captive portal hosted on a Cisco ISE PSN for Central Web Authentication (CWA), the portal is served over HTTPS on TCP port 8443. This is the default port for ISE guest and sponsor portals. The firewal

Web Auth and Guest Services

Question

A network engineer must define a Redirect ACL on a Cisco Wireless LAN Controller. The ACL must force unknown users to authenticate via a captive portal located on a Cisco ISE PSN on another network segment separated by a firewall. Which port must be permitted in the firewall to allow traffic between the Cisco Wireless LAN Controller and Cisco ISE?

Options

  • AUDP port 1812
  • BTCP port 8443
  • CUDP port 1645
  • DTCP port 8445

How the community answered

(31 responses)
  • B
    94% (29)
  • C
    3% (1)
  • D
    3% (1)

Explanation

When a Cisco Wireless LAN Controller (WLC) redirects unauthenticated users to a captive portal hosted on a Cisco ISE PSN for Central Web Authentication (CWA), the portal is served over HTTPS on TCP port 8443. This is the default port for ISE guest and sponsor portals. The firewall between the WLC and the ISE PSN must permit TCP port 8443 inbound to allow clients' browsers to reach the ISE web portal. UDP port 1812 is used for RADIUS authentication between the WLC and ISE, UDP port 1645 is the legacy RADIUS authentication port, and TCP port 8445 is associated with ISE administrative or sponsor portal access. For the captive portal redirect to function correctly, TCP 8443 must be open through the firewall.

Topics

#Captive Portal#Cisco ISE#Cisco WLC#Firewall Ports

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice