QuestionQ1294

Security Fundamentals

A customer wants to offer wireless access to contractors by using a guest portal on Cisco ISE. The portal is also used by employees. A solution has been implemented, but contractors get a certificate error when they try to access the portal. Employees can access the portal without any errors.

Which change must be implemented to allow both the contractors and employees to access the portal?

  • A Install an Internal CA signed certificate on the Cisco ISE.
  • B Install a trusted third-party certificate on the Cisco ISE.
  • C Install an internal CA signed certificate on the contractor devices.
  • D Install a trusted third-party certificate on the contractor devices.
Explanation

Cisco ISE guest portals should use a certificate signed by a well-known public CA when they are accessed by unmanaged or external users. Employees often do not see errors because their corporate devices already trust the organization’s internal CA, but contractors’ devices typically do not. Replacing the portal certificate on Cisco ISE with a trusted third-party certificate allows both groups to trust the portal without browser certificate warnings.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!