Refer to the exhibit. An engineer is troubleshooting a client connectivity issue. The client is in the RUN state, and no traffic is passed after authenticating by using Cisco ISE. Which action resolves the problem?
A.
Configure a different client VLAN after authentication.
B.
Disable the ACL that prevents traffic from being allowed.
B. Disable the ACL that prevents traffic from being allowed.
Explanation:
From the provided logs, the following key information is observed:
The client is in the RUN state, which means it has successfully authenticated and associated with the network.
The AVP[07] Cisco Url-Redirect-ACL is set to BLACKHOLE, which indicates that an ACL is applied to the client, blocking all traffic.
The BLACKHOLE ACL is likely preventing the client from passing any traffic after authentication. To resolve this issue, the ACL must be disabled or modified to allow traffic.
Why This Action?
The BLACKHOLE ACL is explicitly designed to drop all traffic, which explains why the client cannot pass any traffic despite being in the RUN state.
Disabling or modifying the ACL will allow traffic to flow normally.
Why Not the Other Options?
A. Configure a different client VLAN after authentication: The issue is not related to VLAN assignment, as the client is already in the RUN state.
C. Apply a lower WMM QoS: QoS settings would not resolve the issue of traffic being blocked by an ACL.
D. Enable rate-limiting to the client: Rate-limiting would restrict bandwidth but would not resolve the issue of traffic being completely blocked.
Must be A
"url-redirect-acl" only apply as a preauthentication ACL for clients during authentication process. Because the client is already authenticated it have no impact.
good catch, but to disable Blackhole ACL - the choice is B
upvoted 1 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
rrahim
4 days, 9 hours agorrahim
4 days, 9 hours agoraphim
4 months, 1 week agoSeba_o_s
3 months, 3 weeks agoAhcMez
6 months, 3 weeks agorrahim
4 days, 9 hours ago