300-430 Question 224
Select 4An organization is implementing 802.1X authentication for its corporate wireless network using Cisco Identity Services Engine (ISE) as the AAA server. The wireless network is configured in a centralized architecture with a Cisco Wireless LAN Controller (WLC). Which of the following steps are required to properly configure 802.1X and AAA on this network?
- A
Configure the WLC to use the ISE server as the RADIUS server for authentication.
- B
Enable the 'Local Authentication' option on the WLC to bypass AAA and use local user credentials.
- C
Create a Wireless Client Policy in ISE to define authorization rules based on user and device attributes.
- D
Enable 802.1X on the wireless LAN (WLAN) configuration within the WLC.
- E
Ensure that the WLC is added as a network device in ISE with the correct shared secret.
Show answer and explanation
Correct answers: A, C, D, E
Explanation
Implementing 802.1X and AAA with Cisco ISE in a centralized wireless architecture requires configuring the WLC to use ISE as the RADIUS server, enabling 802.1X on the WLAN, and defining policies in ISE for authentication and authorization. Additionally, the WLC must be added as a network device in ISE with the correct shared secret to facilitate secure communication. The 'Local Authentication' option is not used in this scenario as it bypasses AAA entirely.
- A. Correct.
Correct: The WLC must be configured to use the ISE server as the RADIUS server for 802.1X authentication to function properly.
- B. Incorrect.
Incorrect: Enabling 'Local Authentication' bypasses the use of a RADIUS server, which is not aligned with implementing 802.1X and AAA using ISE.
- C. Correct.
Correct: ISE policies are essential for enforcing authentication and authorization rules based on user and device attributes.
- D. Correct.
Correct: 802.1X must be explicitly enabled on the WLAN configuration to enforce authentication for wireless clients.
- E. Correct.
Correct: Adding the WLC as a network device in ISE with the correct shared secret ensures that RADIUS communication between the WLC and ISE is secure and functional.