ETExamTower
Q12Network Access Device AdministrationMultiple answers

Refer to the exhibit. A network engineer is configuring a switch to accept downloadable ACLs from a Cisco ISE server. Which two commands must be run to finish the configuration? (Choose two.)

Question exhibit
Select 2 answers.
← → navigate · a answer
Community votes
B
32% (9)
D
32% (9)
C
25% (7)
A
7% (2)
E
4% (1)
Discussion · 23
10
Correct answer should be B and D. Option C only enables dot1x globally, not for accepting downloadable ACLs.
B, C 3
Selected Answer: BC To configure a switch to accept downloadable ACLs from a Cisco ISE server, the two required commands are: B. ip device tracking: This command turns on tracking of IP device information, which is needed for the ISE server to provide dynamic access policies based on a device's IP address. C. dot1x system-auth-control: This command enables 802.1X authentication on the switch and lets the switch forward authentication requests to the ISE server.
3
Answer is B and D https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/15-mt/sec-user-8021x-15-mt-book/sec-ieee-802x-acl-assign.html Configuring Downloadable ACLs To configure a switch to accept downloadable ACLs or redirect URLs from the RADIUS server during authentication of an attached host, complete this task. SUMMARY STEPS 1. enable 2. configure terminal 3. ip device tracking 4. aaa new-model 5. aaa authorization network default group radius 6. radius-server vsa send authentication 7. interface interface-id 8. ip access-group acl-id in 9. end 10. show running-config interfaceinterface-id 11. copy running-config startup-config
3
For me the two answers are dot1x enable globally and the device ip tracking command. If i do not have dot1x enabled my switch will simply not use the dot1x feature. How can a switch download a dynamic acl from ISE if i do not enable the feature that lets that client authenticate via ISE and based on the result it gets will receive a dACL? the ip tracking device feature is enabled for this purpose: per-user ACL with any SW use ip tracking to re-arrange the ACL to add the host IP instead of any. What this means is that the device ip tracking command lets the switch modify that specific acl with the host ip address /32 address of the device that is connected to that port.
2
I will switch it to B and C. After reading this in the official book I think B&C are correct: "The dot1x system-auth-control command allows for the any source in the provided dACL to be replaced with the IP address of the single device connected to the switch port."
B, D 2
Selected Answer: BD Talking about DACLs, as per https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/15-mt/sec-user-8021x-15-mt-book/sec-ieee-802x-acl-assign.html
B, D 2
Selected Answer: BD https://docs.portnox.com/topics/policy_acp_dacl_cisco
2
B,D sorry, my mistake
B, D 1
Selected Answer: BD My answer according to this documentation: "https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/15-mt/sec-user-8021x-15-mt-book/sec-ieee-802x-acl-assign.html"
1
Option B is correct because it enables the switch to track IP device information, which is required for the ISE server to provide dynamic access policies based on the device's IP address. Without this command, the switch may not be able to provide the needed device information to the ISE server for dynamic policy enforcement. Option C is correct because it enables 802.1X authentication on the switch and lets the switch forward authentication requests to the ISE server. This is required for the ISE server to authenticate users and authorize access based on the user's identity and the device's posture. Created by ChatGPT so read with caution
1
B & D according to the documentation we have: Configuring Downloadable ACLs To configure a switch to accept downloadable ACLs or redirect URLs from the RADIUS server during authentication of an attached host, perform this task. SUMMARY STEPS 1. enable 2. configure terminal 3. ip device tracking 4. aaa new-model 5. aaa authorization network default group radius 6. radius-server vsa send authentication 7. interface interface-id 8. ip access-group acl-id in 9. end
A, C 1
Selected Answer: AC The correct answers are: radius-server attribute 8 include-in-access-req and dot1x system-auth-control. The radius-server attribute 8 include-in-access-req command tells the switch to include RADIUS attribute 8 (user group membership) in the Access-Request packet sent to the RADIUS server. This attribute is used by the RADIUS server to decide which downloadable ACL to send to the switch. The dot1x system-auth-control command enables 802.1X authentication on the switch. This is required for the switch to accept downloadable ACLs from the RADIUS server.
B, C 1
Selected Answer: BC Page 5 at https://www.cisco.com/c/en/us/td/docs/routers/cloud_edge/c8300/software_config/cat8300swcfg-xe-17-book/m-chng-of-auth.pdf
1
Ok, but first you have to enable Dot1x globally to make it work. So C) "dot1x system-auth-control" has higher priority than sending vendor-specific VSA attributes, which are anyway enabled by default. "Step 5. Enable vendor-specific attributes (VSAs) on the switch (which may be enabled by default on the switch already): C9300(config)# radius-server vsa send authentication C9300(config)# radius-server vsa send accounting "
B, C 1
Selected Answer: BC vsa send vendor specific attribute and has nothing to do with CoA, radius-server attribute 8 send the attribute to ISE and has nothing to do with the CoW or dACL but the only 2 commands that affect it are enabling dot1x globally "C" and device tracking, which lets the switch know the IP address of the endpoints connected to its port and will affect the dACL. "B and C"
A, D 1
Selected Answer: AD https://docs.portnox.com/topics/policy_acp_dacl_cisco
C, D 1
Selected Answer: CD Official Exam guide, p. 266. "ip device tracking has been enabled by default since IOS 15.x" so I will assume we're working with a newer switch. That leaves C (enables dot1x globally) and D (lets the switch send VSAs).
1
Sorry, changing to C and E. Just tested this in a Cisco ISE lab. Both B and D were enabled by default (and not in the "show run"). A relates to "framed-ip-address". C. Enables 802.1x globally E. Has the following uses: Auth-proxy is a Cisco feature that: Triggers web-based (HTTP/HTTPS) login prompts Authorizes users based on their credentials Dynamically applies per-user policies like: dACLs (downloadable ACLs) URL redirection SGT tags
C, E 1
Selected Answer: CE See my corrected response below. Sorry.
1
both B and D are enabled by default in the latest IOS.
C, D 1
Selected Answer: CD "radius server vsa send authentication" is needed for the NAD to recognize and use Vendor Specific Attributes. DACLs are sent by ISE as vendor specific attributes dot1x system control enables 802.1X globally
B, D 1
Selected Answer: BD B. ip device tracking D. radius server vsa send authentication 📝 Why Not C? C. dot1x system-auth-control is required only if 802.1X is being used. But downloadable ACLs can also be applied through MAB or WebAuth. So, while it is often used, it is not always required for dACLs. If you're configuring for 802.1X only, C could be a correct choice together with B. But for general dACL use across deployment methods, B and D are the most accurate answers.
B, D 1
Selected Answer: BD According to Cisco documentation.