300-425 Question 293
Single answerAn enterprise network administrator is configuring Cisco Identity Services Engine (ISE) for wireless client authentication. The goal is to ensure that employees use their corporate credentials for network access, while guests are redirected to a captive portal for registration. Which feature in Cisco ISE must be implemented to achieve this behavior?
- A
802.1X Authentication
- B
Central Web Authentication (CWA)
- C
RADIUS Change of Authorization (CoA)
- D
Device Profiling
Show answer and explanation
Correct answer: B
Explanation
Central Web Authentication (CWA) is a feature in Cisco ISE that facilitates guest access by redirecting users to a captive portal for registration. This allows organizations to differentiate between employee and guest users, where employees can authenticate using 802.1X and guests are redirected to a web portal. This configuration aligns with the scenario's requirements.
- A. Incorrect.
802.1X Authentication is a foundational protocol used for authenticating users, but it does not handle captive portal redirection for guests.
- B. Correct.
Central Web Authentication (CWA) is the correct feature to use when implementing a captive portal for guest access in Cisco ISE, while allowing corporate users to authenticate using their credentials.
- C. Incorrect.
RADIUS Change of Authorization (CoA) is used to dynamically update the authorization of a client session, but it is not directly responsible for captive portal redirection.
- D. Incorrect.
Device Profiling is used to identify and classify devices on the network, but it does not manage authentication or captive portal functionality.