Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium
A network security administrator is configuring 802.1X authentication on a Cisco Catalyst switch. The goal is to ensure that only authenticated devices can access the network, and if authentication fails, the port should be placed into a state that prevents any traffic flow. Which 802.1X port control mode should be configured to achieve this strict security requirement?
- AForce Authorized
- BAuto
- CForce Unauthorized
- DMonitor
Show answer & explanationAnswer & explanation
Correct answer: B. Auto
The 'Auto' port control mode (often the default for 802.1X) causes the port to initially be in an unauthorized state. It then attempts authentication. If authentication is successful, the port transitions to an authorized state. If authentication fails, the port remains in an unauthorized state, blocking all traffic, which aligns with the requirement for strict security.
Why the other options are wrong
- A. Force Authorized bypasses 802.1X authentication, allowing all traffic.
- C. Force Unauthorized keeps the port in a permanent unauthorized state, blocking all traffic, even if authentication could succeed.
- D. Monitor mode is not a standard 802.1X port control mode; it sounds like a diagnostic setting.
802.1X Port Control Modes
Settings on a switch port that determine how 802.1X authentication is handled.
- Auto: Requires successful authentication for network access.
- Force Authorized: Bypasses authentication, always grants access.
- Force Unauthorized: Blocks all network access, regardless of authentication.
Memory trick: Auto is 'Ask', Force Authorized is 'Always Yes', Force Unauthorized is 'Always No'.