Q16Web Auth and Guest Services
Which configuration must be set in the Cisco ISE authentication policy to permit Central Web Authentication?
← → navigate · a answer
Community votes
Discussion · 9
A 4
Selected Answer: A
The tasks needed to complete a Cisco ISE WebAuth configuration include these:
Verify that session services are enabled for the guest and sponsor portals.
Set or confirm that the MAB authentication policy will continue after failure due to “User (message authentication code (MAC) not found.”
3
correct A
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html
A 3
Selected Answer: A
A-- this is the guest flow
2
To allow Central Web Authentication, the article says the correct configuration is to use Dot1x and if authentication failed, continue.
2
No. The tasks needed to complete a Cisco ISE WebAuth configuration include these:
Verify that session services are enabled for the guest and sponsor portals.
Set or confirm that the MAB authentication policy will continue after failure due to “User (message authentication code (MAC) not found.”
B 2
Selected Answer: B
The correct answer is - MAB and if authentication failed, continue.
To permit Central Web Authentication (CWA) in a Cisco ISE authentication policy, this configuration is required:
Code snippet
authentication local
authentication mab
authentication dot1x
if authentication failed then continue
Use code with caution. Learn more
The first two lines set up local authentication and MAB as the first two authentication methods. The third line sets 802.1X as the third authentication method. The last line instructs ISE to move on to the next authentication method if authentication fails.
If authentication fails with MAB, ISE will try authentication with 802.1X. If authentication fails with 802.1X, ISE will send the user to the CWA portal.
1
correct.
D 1
Selected Answer: D
Dot1x and if user not found, continue
A 1
Selected Answer: A
Correct: A. MAB and if user not found, continue
This lets unauthenticated guests get redirected to the web portal after MAC auth does not find the user in the database, which is the expected behavior for CWA.