300-430 exam dumps

300-430 practice question 206 of 324

Implementing Cisco Enterprise Wireless Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-430 Question 206

Select 4

A large enterprise has implemented Local Web Authentication (LWA) for guest Wi-Fi access using Cisco Identity Services Engine (ISE) as the authentication server. During testing, users are redirected to the login page after connecting to the SSID, but authentication fails, and guests are unable to gain network access. Which of the following configurations should you verify to resolve the issue?

  1. A

    Ensure that the WLC has the correct RADIUS server settings pointing to the ISE server.

  2. B

    Verify that the ISE server has a valid certificate installed and trusted by client devices.

  3. C

    Confirm that the WLAN is configured for WPA2-Enterprise with 802.1X authentication.

  4. D

    Check that the redirect URL provided by the WLC matches the URL configured in ISE for LWA.

  5. E

    Ensure that the WLC has the appropriate pre-authentication ACL configured.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

Local Web Authentication (LWA) requires proper integration between the WLC and ISE to function correctly. The WLC must have the correct RADIUS server settings to communicate with ISE for authentication. The ISE server must present a valid, trusted certificate to ensure that client devices trust the connection. The redirect URL provided by the WLC must match the configuration in ISE to ensure users are directed to the appropriate login page. Additionally, pre-authentication ACLs on the WLC are required to allow traffic to the login page during the authentication process. WPA2-Enterprise with 802.1X is not applicable to LWA as it uses a web-based method for guest authentication.

  • A. Correct.

    The WLC must have the correct RADIUS server settings pointing to the ISE server for authentication to succeed. Incorrect settings will cause authentication failures.

  • B. Correct.

    The ISE server must have a valid certificate installed and trusted by client devices. If the certificate is invalid or untrusted, users may fail to authenticate due to certificate validation errors.

  • C. Incorrect.

    WPA2-Enterprise with 802.1X is not used in LWA. LWA relies on web-based authentication after redirection, so this configuration is irrelevant in this scenario.

  • D. Correct.

    The redirect URL provided by the WLC must match the URL configured in ISE for LWA. A mismatch can prevent users from being redirected to the correct login page.

  • E. Correct.

    The WLC must have a pre-authentication ACL configured to allow DNS and HTTP/HTTPS traffic before authentication. Without this, redirection and authentication will fail.

Timed practice exam

Take a 300-430 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam