Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-701 Exam - Topic 6 Question 126 Discussion

[Endpoint Protection and Detection]A Cisco ISE engineer configures Central Web Authentication (CWA) for wireless guest access and must have the guest endpoints redirect to the guest portal for authentication and authorization. While testing the policy, the engineer notices that the device is not redirected and instead gets full guest access. What must be done for the redirect to work?
D) Add the DACL name for the Airespace ACL configured on the WLC in the Common Tasks section of the authorization profile for the authorization policy line that the unauthenticated devices hit.
A) Tag the guest portal in the CWA part of the Common Tasks section of the authorization profile for the authorization policy line that the unauthenticated devices hit.
B) Use the track movement option within the authorization profile for the authorization policy line that the unauthenticated devices hit.
C) Create an advanced attribute setting of Cisco:cisco-gateway-id=guest within the authorization profile for the authorization policy line that the unauthenticated devices hit.

Cisco 350-701 Exam - Topic 6 Question 126 Discussion

Actual exam question for Cisco's 350-701 exam
Question #: 126
Topic #: 6
[All 350-701 Questions]

[Endpoint Protection and Detection]

A Cisco ISE engineer configures Central Web Authentication (CWA) for wireless guest access and must have the guest endpoints redirect to the guest portal for authentication and authorization. While testing the policy, the engineer notices that the device is not redirected and instead gets full guest access. What must be done for the redirect to work?

Show Suggested Answer Hide Answer
Suggested Answer: D

To enable CWA for wireless guest access, the ISE engineer needs to configure the following steps on the ISE server:

Create a guest portal with the desired settings and appearance.

Create an authorization profile that references the guest portal and the DACL name for the Airespace ACL configured on the WLC. The DACL name must match the name of the ACL on the WLC exactly. The authorization profile also needs to have the common tasks of Web Redirection and Web Authentication enabled.

Create an authorization policy that matches the unauthenticated devices based on the MAC address or other criteria and applies the authorization profile created in the previous step.

The DACL name is required for the WLC to apply the correct ACL to the guest endpoints and redirect them to the guest portal. Without the DACL name, the WLC will not know which ACL to use and may grant full guest access to the endpoints. Therefore, the correct answer is D.


Some possible references are:

Central Web Authentication (CWA) for guests with ISE

Understand And Troubleshoot Central Web-Authentication (CWA) In Guest Anchor Set-Up

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Release 17.3.0 - Guest Access

Contribute your Thoughts:

0/2000 characters
Stephaine
3 days ago
Track movement? Not sure about that.
upvoted 0 times
...
Jenise
8 days ago
I feel B could work too.
upvoted 0 times
...
Marge
13 days ago
Tagging the portal is crucial for redirection.
upvoted 0 times
...
Stephaine
19 days ago
Why A?
upvoted 0 times
...
Marge
24 days ago
I think A is the right choice.
upvoted 0 times
...
Pilar
29 days ago
Definitely sounds like a configuration issue with the authorization profile.
upvoted 0 times
...
Craig
1 month ago
Wait, is it really that simple?
upvoted 0 times
...
Ashley
1 month ago
I thought it was about the DACL name instead?
upvoted 0 times
...
Paola
1 month ago
Totally agree, that's the right move!
upvoted 0 times
...
Jose
2 months ago
You need to tag the guest portal in the CWA section.
upvoted 0 times
...
Leota
2 months ago
I definitely remember that the authorization profile plays a key role here, but I’m torn between tagging the portal and creating an advanced attribute.
upvoted 0 times
...
Daniel
2 months ago
I feel like the track movement option might be relevant, but it seems more related to tracking users rather than redirecting them.
upvoted 0 times
...
Oretha
2 months ago
I think I practiced a similar question where we had to configure redirects for guest access, but I can't recall if it was about DACLs or something else.
upvoted 0 times
...
Yasuko
2 months ago
I remember something about needing to tag the guest portal in the authorization profile, but I'm not entirely sure if that's the only step needed.
upvoted 0 times
...

Save Cancel