Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-430 Exam - Topic 11 Question 104 Discussion

An engineer has implemented 802.1x authentication on the wireless network utilizing the internal database of a RADIUS server. Some clients reported that they are unable to connect. After troubleshooting, it is found that PEAP authentication is failing. A debug showed the server is sending an Access- Reject message. Which action must be taken to resolve authentication?
B) Disable the server certificate to be validated on the client.
A) Use the user password that is configured on the server.
C) Update the client certificate to match the user account.
D) Replace the client certificates from the CA with the server certificate.

Cisco 300-430 Exam - Topic 11 Question 104 Discussion

Actual exam question for Cisco's 300-430 exam
Question #: 104
Topic #: 11
[All 300-430 Questions]

An engineer has implemented 802.1x authentication on the wireless network utilizing the internal database of a RADIUS server. Some clients reported that they are unable to connect. After troubleshooting, it is found that PEAP authentication is failing. A debug showed the server is sending an Access- Reject message. Which action must be taken to resolve authentication?

Show Suggested Answer Hide Answer
Suggested Answer: B

If PEAP authentication is failing and the server is sending an Access-Reject message, one possible action to resolve the issue is to disable the server certificate validation on the client. This means that the client device will not check the authenticity of the RADIUS server's certificate, which can sometimes resolve connection issues, especially if there is a problem with the certificate chain or trust settings. However, this should be done with caution as it reduces the security of the authentication process.Reference: CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide


Contribute your Thoughts:

0/2000 characters
Tammi
2 days ago
I disagree, B might be the way to go. Disabling the server certificate could help clients connect.
upvoted 0 times
...
Wendell
7 days ago
I think option A is the best choice. The user password should match what's on the server.
upvoted 0 times
...
Johnna
12 days ago
I’m leaning towards option C for the client certificate update.
upvoted 0 times
...
Sharan
17 days ago
Definitely need to check the user password on the server.
upvoted 0 times
...
Princess
23 days ago
Wait, why would you disable certificate validation?
upvoted 0 times
...
Torie
28 days ago
I think option B is risky!
upvoted 0 times
...
Karrie
1 month ago
Sounds like a certificate issue.
upvoted 0 times
...
Sherill
1 month ago
I’m a bit confused about the Access-Reject message. Does that mean we should focus on the user password or the certificates?
upvoted 0 times
...
Angelyn
1 month ago
This question feels familiar; I think we practiced something similar where we had to update certificates to resolve authentication failures.
upvoted 0 times
...
Douglass
2 months ago
I think disabling the server certificate validation could be risky, but it might help with the connection issues.
upvoted 0 times
...
Florencia
2 months ago
I remember something about client certificates needing to match the server's requirements, but I'm not sure which option that relates to.
upvoted 0 times
...

Save Cancel