Which of the following statements are correct about Central Web Authentication (CWA)?
CWA centralizes the guest portal and credential validation on an external authentication system such as Cisco ISE. The controller receives the RADIUS redirection policy during Layer 2 admission and redirects the client’s web traffic to the central portal. Consequently, the controller does not need its own local WebAuth certificate; the portal requires the certificate. The end-to-end flow includes Layer 2 authentication/policy enforcement and Layer 3 web redirection, so it is not purely a Layer 3 process. A controller alone is insufficient because CWA depends on the external authentication server and portal.
Community Discussion