Free 300-715 Exam Braindumps (page: 42)

Page 41 of 93



Refer to the exhibit. An engineer must configure central web authentication on the Cisco Wireless LAN Controller to use Cisco ISE for all guests connected to the wireless network. The Cisco Wireless LAN Controller and the Cisco ISE were configured, and the RADIUS-related ports were opened on the firewall.
Which additional port must be opened to allow communication between the Cisco Wireless LAN Controller and Cisco ISE?

  1. TCP 80
  2. UDP 1645
  3. UDP 1813
  4. TCP 8443

Answer(s): D

Explanation:

In a Central Web Authentication (CWA) setup, Cisco Wireless LAN Controller (WLC) interacts with Cisco ISE to redirect guest users to a web portal for authentication. The additional port required for this communication is TCP 8443, which is used by Cisco ISE for the web portal redirection and communication with the WLC.



The Cisco Wireless LAN Controller and guest portal must be set up in Cisco ISE. These configurations were performed:
configured all the required Cisco Wireless LAN Controller configurations added the wireless controller to Cisco ISE network devices
created an endpoint identity group configured credentials to be sent by email configured the SMTP server
configured an authorization profile with redirection to the guest portal and redirected the access control list configured an authentication policy for MAB users
created an authorization policy
Which two components must be created to complete the configuration? (Choose two.)

  1. sponsor portal
  2. hotspot guest portal
  3. sponsor group
  4. self-registered guest portal
  5. guest type

Answer(s): D,E

Explanation:

In a Cisco ISE guest access deployment, several components must be configured to provide a complete guest experience. In this scenario, many of the necessary configurations have already been completed (such as network device settings, SMTP server configuration, and redirection via the authorization profile). However, to fully enable guest access via a Cisco Wireless LAN Controller with a guest portal, two additional components must be created:
Self-Registered Guest Portal:
Since the configuration already includes settings for sending credentials by email and redirection to a guest portal, the environment is set up for self-service guest registration. The self-registered guest portal is the web interface where guests can register themselves to obtain access. Without this portal, guests would not have a method to register and receive their credentials.
Guest Type:
Cisco ISE uses guest types to categorize and manage different kinds of guest accounts (such as contractors, visitors, etc.). Creating a guest type is essential because it defines the attributes and policies that apply to the guest sessions. This classification helps enforce the proper access controls and facilitates reporting.



A network engineer must define a Redirect ACL on a Cisco Wireless LAN Controller. The ACL must force unknown users to authenticate via a captive portal located on a Cisco ISE PSN on another network segment separated by a firewall.
Which port must be permitted in the firewall to allow traffic between the Cisco Wireless
LAN Controller and Cisco ISE?

  1. UDP port 1812
  2. TCP port 8443
  3. UDP port 1645
  4. TCP port 8445

Answer(s): B

Explanation:

When configuring a Redirect ACL on a Cisco Wireless LAN Controller (WLC) to force unknown users to authenticate via a captive portal on a Cisco ISE PSN, the communication between the WLC and the ISE PSN for web authentication is conducted over HTTPS. Cisco ISE uses TCP port 8443 for its web-based captive portal redirection services.
Allowing TCP port 8443 through the firewall ensures that the redirection traffic from the WLC reaches the ISE PSN without interruption. The other ports listed are associated with RADIUS (UDP ports 1812 for authentication and 1645 for legacy RADIUS) or a non-standard port (TCP 8445), none of which are used for the captive portal redirection.



An engineer is deploying a new guest WLAN for a company. The company wants this WLAN to use a sponsored guest portal for secure guest access. The wireless LAN controller must direct the guests to a web page on Cisco ISE for authentication.
Which type of authentication must be configured for the guest portal in Cisco ISE?

  1. CWA
  2. web portal
  3. EWA
  4. DWA

Answer(s): A

Explanation:

Central Web Authentication (CWA) must be configured for the guest portal in Cisco ISE. CWA allows the wireless LAN controller to redirect guest users to a web portal hosted on Cisco ISE for authentication, which is the standard approach for sponsored guest access.






Post your Comments and Discuss Cisco® 300-715 exam with other Community members:

Exam Discussions & Posts