QuestionQ17

Security for Wireless Client Connectivity

Implementing 802.1X on an access point requires three steps. Place the following steps in the correct sequence:

I. Configure ISE with the appropriate security policies to authenticate and authorize traffic from the AP.

II. Enable the 802.1X supplicant on the AP, either globally or on a per-AP basis.

III. Configure the local switch port for 802.1X and specify the back-end ISE server as the authentication server.

Explanation

The implementation sequence is to first enable and provision the AP as the 802.1X supplicant (II), then configure the connected switch port as the 802.1X authenticator and point it to ISE through RADIUS (III), and finally configure ISE authentication and authorization policies for the AP traffic (I). This matches Cisco’s documented configuration flow: AP supplicant, switch, then ISE. The AP needs its supplicant credentials before the switch begins enforcing port authentication, and the switch needs its RADIUS/ISE settings to relay EAP authentication. Option D is a plausible design-preparation order, but it does not follow Cisco’s documented staged implementation sequence.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!