H12-725_V4.0 · Question #259
The network of a certain campus is as shown in the figure, where SW1 is the authentication point device. Which of the following descriptions of network access control are correct? (Multiple choice)
The correct answer is B. If MAC priority Portal authentication is deployed, after the visitor is disconnected, he or she can C. If 802.1X authentication is deployed, EAP packet transparent transmission configuration needs to D. If Portal authentication is deployed, iMaster can. Options B, C, and D are correct because each accurately describes a real behavioral or configuration requirement of its respective authentication method. In MAC Priority Portal authentication (B), after a visitor completes Portal authentication once and disconnects, the device…
Question
The network of a certain campus is as shown in the figure, where SW1 is the authentication point device. Which of the following descriptions of network access control are correct? (Multiple choice)
Exhibit
Options
- AIf MAC address authentication is deployed, there is no need to collect the MAC addresses of all
- BIf MAC priority Portal authentication is deployed, after the visitor is disconnected, he or she can
- CIf 802.1X authentication is deployed, EAP packet transparent transmission configuration needs to
- DIf Portal authentication is deployed, iMaster can
How the community answered
(60 responses)- A27% (16)
- B73% (44)
Explanation
Options B, C, and D are correct because each accurately describes a real behavioral or configuration requirement of its respective authentication method. In MAC Priority Portal authentication (B), after a visitor completes Portal authentication once and disconnects, the device saves their MAC address - so upon reconnection, they bypass the Portal page and regain access directly without re-entering credentials. For 802.1X (C), EAP packets are link-layer frames that cannot be routed natively; any intermediate switches between the client and the authenticator (SW1) must be configured for EAP transparent transmission so these packets reach the authentication point intact. For Portal with iMaster NCE (D), Huawei's iMaster platform integrates with Portal to push policies, manage user sessions, and control access centrally - this is a supported and standard deployment scenario.
Option A is incorrect because MAC address authentication does require pre-collecting and registering the MAC addresses of all authorized devices into the authentication server's database; without a known-MAC whitelist, the system has nothing to authenticate against.
Memory tip: Think of the four methods by what they need: MAC auth needs a list (pre-registered MACs); MAC-priority Portal remembers after the first login; 802.1X needs EAP to travel through (transparent transmission); and Portal with iMaster needs a manager (centralized control). If a statement says MAC auth skips the list, it's wrong.
Topics
Community Discussion
No community discussion yet for this question.
