300-715 · Question #387
An engineer must use Cisco ISE to provide network access to endpoints that cannot support 802.1X. The endpoint MAC addresses must be allowlisted by configuring an endpoint identity group. These config
The correct answer is C. authorization policy that has the PermitAccess permission and matches the allowlist identity. In Cisco ISE, MAB (MAC Authentication Bypass) requires both an authentication policy and an authorization policy. The scenario already has an authentication policy configured for MAB users and an endpoint identity group (allowlist) with the MAC addresses enrolled. The missing pie
Question
An engineer must use Cisco ISE to provide network access to endpoints that cannot support 802.1X. The endpoint MAC addresses must be allowlisted by configuring an endpoint identity group. These configurations were performed:
- configured an identity group named allowlist
- configured the endpoints to use the MAC address of incompatible
802.1X devices
- added the endpoints to the allowlist identity group
- configured an authentication policy for MAB users
What must be configured?
Options
- Alogical profile that matches the allowlist identity group based on the configured policy
- Bauthorization profile that has the PermitAccess permission and matches the allowlist identity
- Cauthorization policy that has the PermitAccess permission and matches the allowlist identity
- Dauthentication profile that has the PermitAccess permission and matches the allowlist identity
How the community answered
(43 responses)- B2% (1)
- C95% (41)
- D2% (1)
Explanation
In Cisco ISE, MAB (MAC Authentication Bypass) requires both an authentication policy and an authorization policy. The scenario already has an authentication policy configured for MAB users and an endpoint identity group (allowlist) with the MAC addresses enrolled. The missing piece is an authorization policy - this is what ISE evaluates after authentication to determine what access to grant. The authorization policy must reference the allowlist identity group as a condition and apply the PermitAccess result. Option B is wrong because an authorization profile defines the access attributes (e.g., VLAN, ACL), while an authorization policy is the rule that matches conditions (like identity group membership) and maps them to that profile or a result like PermitAccess. Option A (logical profile) and D (authentication profile) are not valid ISE constructs for this purpose.
Topics
Community Discussion
No community discussion yet for this question.