QuestionQ30

Security for Wireless Client Connectivity

An engineer must configure a CPU ACL that blocks web-management traffic to the controller while still allowing guests to access a Web Authentication Redirect page.

To which IP address must guest-client HTTPS traffic be allowed for this to function?

Explanation

Guest HTTPS traffic must be permitted to the virtual interface IP address because the controller uses that address as the redirect destination for the Web Authentication login page. With CPU ACLs that block HTTP/HTTPS, Cisco requires an allow rule for the virtual IP on TCP port 443 when secure web authentication is enabled. The controller management IP is the strongest distractor, but it is the management-plane address rather than the guest web-authentication redirect address.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!