ETExamTower
Q49Secure Network Access, Visibility, and Enforcement

Refer to the exhibit. What happens when this device attempts to connect to the port?

Question exhibit
← → navigate · a answer
Community votes
B
40% (4)
C
30% (3)
A
20% (2)
D
10% (1)
Discussion · 24
B 11
Selected Answer: B There is no MAB in the config. So any question with MAB working is false. D is fasle. Dot1x config is correct. Since there is no info that the client is misconfigured, it is B
6
D is correct as we don't know if the device "will be allowed" (i. e. options A, B, C). Instead "ISE can use policy to determine the access level" = option D. In this case, the new style of auth. configuration is used with "policy-map type control subscriber", which provides a very wide range of parameters by which connected devices and their sessions can be matched and authenticated / authorized / denied. All types of authentication can be used - Dot1X, MAB, WebAuth. Example: policy-map type control subscriber CONCURRENT_DOT1X_MAB_WEBAUTH event session-started match-all 10 class always do-until-failure 10 authenticate using mab priority 20 20 authenticate using dot1x priority 10 (rest ommited for brevity) Reference: https://www.cisco.com/en/US/docs/ios-xml/ios/san/configuration/xe-3se/3850/san-cntrl-pol.html
6
Sorry, I meant B, not A
4
B is the answer guys. Cheers
4
Hello, maybe I'm wrong but : - A and D are wrong answers because "mab" is missing in the interface configuration Regarding 802.1X : The interface configuration is OK. Even if there is no information regarding the policies, the supplicant (which supports 802.1X (a notebook for instance)) can communicate with the Authenticator (the swich) using the 801.1X protocol. And thus, the answer C should be excluded. The only answer which remains is B. And more precisely regarding the answer B : It is sure that "802.1X will work" but it is not that "the device will be allowed on the network" (because it depends on the Authentication as well as the Authorization (which are validated and authorized by the server (ISE))
C 3
Selected Answer: C 802.1X will not work and the device will not be allowed network access
B 3
Selected Answer: B look at the description on the port, it says dot1x port. That leads me to think that B is the correct answer. The device (workstation) will be allowed on the network.
2
Even with the new style policy maps & service polices (IBNS v2) you still need mab enabled on the switch port, so the answer is A.
2
... ok after thinking about this question again I need your help guys WHAT DEVICE - this question makes no sense, what do they mean, a PC, Printer, Phone, Access Point, I dont get it??
2
The "authentication port-control auto" command is not missing :) The "access-session port-control auto" command tells the switch port to rely on 802.1X authentication for access control. Devices need to authenticate successfully to get access, and the switch automatically grants access after successful authentication.
2
I am so very blind. Never mind the C.... completely wrong on my side.
2
That could be true, however, on the catalyst switch (9300) I work with, no shutdown is not shown by show run int ... . Only shutdown would be shown. If we do not see anything like that then no shutdown has been applied.
B 2
Selected Answer: B i am not sure about this, but since authentication port-control auto is not configed on the switch, then no authentication will be forced in that case, and the device will get connected.
1
i think A because there is no "mab" command in the provided config.
1
C or D
D 1
Selected Answer: D it is policy based decision and either MAB Dot1x web auth or whatever can be used
1
Looks like something is missing in the question. "What will occur when this device" - what is this device? authentication port-control auto is missing from the config so it will not be forced by the switch to start authentication = device will just be placed into the access vlan, in fact MAB is not cofnigured for authenticaiton, but the device, while not being asked, will present itself with MAC and just be allowed? I will vote for A
A 1
Selected Answer: A Looks like something is missing in the question. "What will occur when this device" - what is this device? authentication port-control auto is missing from the config so it will not be forced by the switch to start authentication = device will just be placed into the access vlan, in fact MAB is not cofnigured for authenticaiton, but the device, while not being asked, will present itself with MAC and just be allowed? I will vote for A
A 1
Selected Answer: A I will go with A: In the given configuration, the line "dot1x pae authenticator" is present. This command makes the switch interface act as an authenticator for 802.1X authentication. However, the configuration does not include any specific 802.1X authentication settings such as the EAP (Extensible Authentication Protocol) method or RADIUS server information. Additionally, the line "switchport mode voice vlan 44" indicates that the interface is configured to use a Voice VLAN. This suggests that the device connecting to this port might be a VoIP phone, which typically uses MAB for authentication rather than 802.1X. Therefore, when this device tries to connect to the port, 802.1X authentication will not work because it is not configured properly. However, since MAB is enabled by default when 802.1X fails, MAB will start and allow the device on the network.
1
There is a voice vlan in the config, so I would assume there is a desktop phone and the config is missing MAB.
C 1
Selected Answer: C C it's so easy. The config is missing "dot1x pae authenticatior" so 802.1x will not work. MAB also will not work since the interface is missing mac auth config
C 1
Selected Answer: C Did anyone notice the command: No shutdown is not used? The interface is turned off, and therefore it is c
1
This is the only correct answer. We are using IBNS2.0 here and it seems the default policy is in use, so both MAB and .1x can be used. Source: I work with ISE & Switches everyday :)
1
Incorrect, the mab command is not needed at the interface level. policy-map type control subscriber TEST4 event session-started match-all 10 class always do-until-failure 10 authenticate using dot1x priority 10 20 authenticate using mab priority 20 event authentication-failure match-first 10 class DOT1X_FAILED do-until-failure 10 terminate dot1x 20 class MAB_FAILED do-until-failure 10 terminate mab 20 authenticate using dot1x priority 10 30 class DOT1X_NO_RESP do-until-failure 10 terminate dot1x 20 authentication-restart 60 40 class always do-until-failure 10 terminate mab 20 terminate dot1x 30 authentication-restart 60 event agent-found match-all 10 class always do-until-failure 10 terminate mab 20 authenticate using dot1x priority 10 event authentication-success match-all 10 class always do-until-failure 10 activate service-template DEFAULT_LINKSEC_POLICY_SHOULD_SECURE !