ETExamTower
Q28Endpoint ComplianceMultiple answers

Which two ports must be permitted between Cisco ISE and the client when configuring posture on Cisco ISE? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
B
50% (4)
C
38% (3)
A
13% (1)
D
0% (0)
E
0% (0)
Discussion · 5
4
The provided answer is correct. https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/install_guide/b_ise_InstallationGuide23/b_ise_InstallationGuide23_chapter_0110.pdf
B, C 2
Selected Answer: BC From “Cisco ISE Ports Reference, Release 3.0”: For posture “Discovery (Client side)” / “Assessment / Heartbeat” the TCP 8905 (HTTPS) port is used. Cisco +1 For Web Portal / Client Provisioning / My Devices / Guest Portal etc., TCP 8443 is used (default in the 8000‑8999 range).
B, C 2
Selected Answer: BC For Cisco ISE posture, you need to think about what the client (supplicant/AnyConnect agent) talks to on ISE (NOT on the client): Discovery (client-side): TCP/80 → but ISE itself redirects this to 8443 TCP/8905 → used by the posture/Client Provisioning service (ISE presents the Admin cert here) Policy Service Node (ISE side): TCP/8443 (Portal cert) TCP/8905 (Posture & client provisioning cert) So, the two ports required between ISE and the client are: B. TCP 8905 and C. TCP 8443 (TCP/80 isn’t strictly required once redirection is in place.) https://community.cisco.com/t5/network-access-control/firewall-ports-between-supplicant-and-ise/td-p/4887237
A, B 1
Selected Answer: AB , port 80 and 8905, A and B
1
Incorrect. The correct answer is B & C Discovery (Policy Service Node side): TCP/8443, 8905 (HTTPS) https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_7.html Doc for ISE 3.0