300-715 · Question #89
Refer to the exhibit. A network engineers configuring the switch to accept downloadable ACLs from a Cisco ISC server. Which two commands should be run to complete the configuration? (Choose two)
The correct answer is D. ip device tracking E. dot1x system-auth-control. For downloadable ACLs (dACLs) from Cisco ISE to work on a switch, two foundational commands are required beyond basic RADIUS configuration: (D) ip device tracking enables the IP Device Tracking feature, which maintains a table of IP-to-MAC-to-port bindings. This is required becau
Question
Refer to the exhibit. A network engineers configuring the switch to accept downloadable ACLs from a Cisco ISC server. Which two commands should be run to complete the configuration? (Choose two)
Exhibit
Options
- Aaaa authorization auth-proxy default group radius
- Bradius server vsa sand authentication
- Cradius-server attribute 8 include-in-access-req
- Dip device tracking
- Edot1x system-auth-control
How the community answered
(37 responses)- A16% (6)
- B3% (1)
- C5% (2)
- D76% (28)
Explanation
For downloadable ACLs (dACLs) from Cisco ISE to work on a switch, two foundational commands are required beyond basic RADIUS configuration: (D) ip device tracking enables the IP Device Tracking feature, which maintains a table of IP-to-MAC-to-port bindings. This is required because dACLs are applied per-user based on IP address, and the switch must track which IP belongs to which port/session to apply the correct ACL. (E) dot1x system-auth-control globally enables 802.1X authentication on the switch - this is a prerequisite for port-based authentication features, including the session management that makes dACL application possible. Without both commands, the switch cannot properly receive and apply the per-session ACLs pushed by ISE.
Topics
Community Discussion
No community discussion yet for this question.
