Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2ArchitectureMedium
A network architect is designing a network for a new branch office that will host a small number of users and critical IoT devices. The design requires robust security for both wired and wireless access, simplified management, and the ability to integrate with the corporate network's Identity Services Engine (ISE) for centralized authentication. Which network security and access control mechanism is best suited for this scenario?
- AMAC address filtering on access points
- BOpen Wi-Fi with a captive portal
- C802.1X with centralized AAA (Authentication, Authorization, Accounting)
- DPre-shared keys (PSKs) for Wi-Fi and static port security for wired
Show answer & explanationAnswer & explanation
Correct answer: C. 802.1X with centralized AAA (Authentication, Authorization, Accounting)
802.1X provides robust port-based authentication for both wired and wireless clients. When combined with a centralized AAA server like Cisco ISE, it enables dynamic policy assignment, consistent access control, and simplified management for diverse devices, aligning perfectly with the requirements for robust security and integration.
Why the other options are wrong
- A. MAC address filtering is easily spoofed, not scalable, and does not integrate with ISE for centralized policy enforcement.
- B. Open Wi-Fi with a captive portal offers minimal security and does not provide the robust access control or integration with ISE required for critical devices.
- D. Pre-shared keys for Wi-Fi are less secure and harder to manage at scale, and static port security lacks dynamic policy capabilities and ISE integration.
802.1X Authentication
An IEEE standard for port-based network access control, providing an authentication mechanism to devices wishing to attach to a LAN or WLAN.
- Authenticates devices before granting network access.
- Uses a supplicant (client), authenticator (switch/AP), and authentication server (AAA/RADIUS).
- Supports various EAP methods for strong authentication.
- Enables dynamic VLAN assignment and policy enforcement.
Memory trick: Access Control: MAC, PSK, 802.1X, Open - Who gets in?