ETExamTower
Q16Web Auth and Guest Services

Which configuration must be set in the Cisco ISE authentication policy to permit Central Web Authentication?

← → navigate · a answer
Community votes
A
67% (4)
B
17% (1)
D
17% (1)
C
0% (0)
Discussion · 9
A 4
Selected Answer: A The tasks needed to complete a Cisco ISE WebAuth configuration include these: Verify that session services are enabled for the guest and sponsor portals. Set or confirm that the MAB authentication policy will continue after failure due to “User (message authentication code (MAC) not found.”
3
correct A https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html
A 3
Selected Answer: A A-- this is the guest flow
2
To allow Central Web Authentication, the article says the correct configuration is to use Dot1x and if authentication failed, continue.
2
No. The tasks needed to complete a Cisco ISE WebAuth configuration include these: Verify that session services are enabled for the guest and sponsor portals. Set or confirm that the MAB authentication policy will continue after failure due to “User (message authentication code (MAC) not found.”
B 2
Selected Answer: B The correct answer is - MAB and if authentication failed, continue. To permit Central Web Authentication (CWA) in a Cisco ISE authentication policy, this configuration is required: Code snippet authentication local authentication mab authentication dot1x if authentication failed then continue Use code with caution. Learn more The first two lines set up local authentication and MAB as the first two authentication methods. The third line sets 802.1X as the third authentication method. The last line instructs ISE to move on to the next authentication method if authentication fails. If authentication fails with MAB, ISE will try authentication with 802.1X. If authentication fails with 802.1X, ISE will send the user to the CWA portal.
1
correct.
D 1
Selected Answer: D Dot1x and if user not found, continue
A 1
Selected Answer: A Correct: A. MAB and if user not found, continue This lets unauthenticated guests get redirected to the web portal after MAC auth does not find the user in the database, which is the expected behavior for CWA.