Troubleshooting Central Web Authentication for Cisco Exam 400-351

Check Configuration for Resolving ISE Guest Login Portal Redirect Issue

Question

You are the network administrator at ACME Corporation and currently troubleshooting a Central Web Authentication issue where the guest users are not being redirected to the ISE guest login portal.

You have verified that all configuration on the ISE is correct and that the ISE is sending the redirect URL for the client.

Which configuration check can help to resolve the issue?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D. E. F.

C.

The issue being faced is that the guest users are not being redirected to the ISE guest login portal during Central Web Authentication. To troubleshoot this issue, the administrator has verified that the ISE is sending the redirect URL for the client, and all configuration on the ISE is correct. To resolve the issue, the administrator should perform the following configuration check:

C. Verify if AAA override is enabled for the guest SSID.

Explanation: AAA override allows an SSID to override the global RADIUS server settings configured on a WLC, and use its own RADIUS server settings for authentication and accounting purposes. In this case, enabling AAA override for the guest SSID will ensure that the correct RADIUS server settings are used for guest authentication, which may be different from the global settings. Without AAA override, the WLC will use the global RADIUS server settings, which may not be configured for guest authentication, and hence the guest users will not be redirected to the ISE guest login portal.

The other options mentioned are not relevant to the issue at hand or are not required for Central Web Authentication.

  • Option A is related to Layer 2 security and does not have any impact on Central Web Authentication.
  • Option B is related to the authentication priority and does not impact the redirection of guest users to the ISE guest login portal.
  • Option D is related to Secure Network Mobility (SNMO) NAC and is not required for Central Web Authentication.
  • Option E is related to RADIUS accounting interim update and is not required for Central Web Authentication.
  • Option F is related to RFC 3567 support and is not required for Central Web Authentication.