Configuring Acceptable Use-Policy Web Authentication without User Credentials - CCIE Wireless Written Exam

Enable Web Authentication for H-REAP Local Switching Branch Networks

Question

You have implemented a branch network using H-REAP local switching.

You have been asked to enable an acceptable use-policy web authentication page, without requiring users to enter credentials and login.

Users should only have to accept the login terms.

Which two solutions should you implement? (Choose two.)

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D. E.

CE.

H-REAP (Hybrid Remote Edge Access Point) local switching is a Cisco WLAN deployment model that allows branch office Cisco Aironet wireless access points (APs) to locally switch WLAN client traffic without sending it through the corporate WAN.

To enable an acceptable use-policy web authentication page without requiring users to enter credentials and login, there are a couple of solutions that can be implemented:

A. Enable a web policy of conditional web redirect: This solution enables the wireless LAN controller (WLC) to redirect users to a specific URL upon opening a web browser. The URL can be the acceptable use-policy web authentication page that contains the terms and conditions for accessing the wireless network. This solution does not require users to enter any credentials, but it requires that the WLC is configured with the URL of the web authentication page.

E. Enable a web policy of passthrough: This solution allows wireless clients to access the network without authentication, but their traffic will be limited until they accept the terms and conditions of the acceptable use-policy web authentication page. Once the user accepts the terms and conditions, they will gain full network access. This solution requires that the WLC is configured with the URL of the web authentication page, but it does not require users to enter any credentials.

B. Use an external web server for the web authentication page: This solution involves hosting the acceptable use-policy web authentication page on an external web server. The WLC can then redirect users to this web server upon opening a web browser. This solution does not require users to enter any credentials, but it requires an external web server and appropriate configuration of the WLC.

C. Use the internal web server for the web authentication page: This solution involves hosting the acceptable use-policy web authentication page on an internal web server that is connected to the WLC. The WLC can then redirect users to this web server upon opening a web browser. This solution does not require users to enter any credentials, but it requires an internal web server and appropriate configuration of the WLC.

D. Implement a pre-authentication ACL to allow web authentication page traffic: This solution involves configuring an access control list (ACL) on the AP to allow traffic from wireless clients to the acceptable use-policy web authentication page. This solution requires users to enter their credentials to access the web authentication page, which is not in line with the requirement mentioned in the question.

In summary, the two solutions that should be implemented to enable an acceptable use-policy web authentication page without requiring users to enter credentials and login are:

A. Enable a web policy of conditional web redirect. E. Enable a web policy of passthrough.