350-701 · Question #710
Which action configures the iEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?
The correct answer is C. Add MAB into the switch to allow redirection to a Layer 3 device for authentication. To support Layer 3 authentication with IEEE 802.1X Flexible Authentication, a common approach is to configure MAC Authentication Bypass (MAB) on the switch, allowing devices to be redirected to a Layer 3 authentication mechanism like a web portal.
Question
Which action configures the iEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?
Options
- AModify the Dot1x configuration on the VPN server to send Layer 3 authentications to an external
- BIdentify the devices using this feature and create a policy that allows them to pass Layer 2
- CAdd MAB into the switch to allow redirection to a Layer 3 device for authentication.
- DConfigure WebAuth so the hosts are redirected to a web page for authentication.
How the community answered
(21 responses)- A10% (2)
- B5% (1)
- C81% (17)
- D5% (1)
Why each option
To support Layer 3 authentication with IEEE 802.1X Flexible Authentication, a common approach is to configure MAC Authentication Bypass (MAB) on the switch, allowing devices to be redirected to a Layer 3 authentication mechanism like a web portal.
Modifying Dot1x configuration on a VPN server is unrelated to configuring the 802.1X Flexible Authentication feature on a switch for Layer 3 authentication of local network devices.
Simply identifying devices and allowing them to pass Layer 2 is a generic statement and does not specifically configure 802.1X Flexible Authentication to enable Layer 3 authentication mechanisms.
Configuring MAC Authentication Bypass (MAB) on the switch allows devices that don't support 802.1X to gain initial network access based on their MAC address. Once MAB authenticates the device, the 802.1X Flexible Authentication feature can then redirect the host to a Layer 3 device (e.g., a web server for WebAuth) for a secondary, more robust authentication process, thus enabling Layer 3 authentication mechanisms.
While WebAuth (web authentication) is a Layer 3 authentication mechanism, the action of 'Configure WebAuth' itself is incomplete; it must be integrated with the 802.1X Flexible Authentication feature, often via MAB, to enable the initial network access and redirection from the switch.
Concept tested: 802.1X Flexible Authentication Layer 3 integration
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/security/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_0100.html
Topics
Community Discussion
No community discussion yet for this question.