An engineer set up RADIUS for WLC management to harden the configuration. Read-only access must be provided to a user. Which Service-Type attribute must be configured on the RADIUS server to meet this requirement?
To provide read-only access to a user for WLC (Wireless LAN Controller) management via RADIUS, the Service-Type attribute must be set to NAS Prompt on the RADIUS server. This attribute allows the user to access the WLC in a read-only mode, preventing any configuration changes.
Explanation of the options:
A. NAS Prompt: This is correct. The NAS Prompt Service-Type attribute provides read-only access to the WLC, allowing the user to view configurations but not modify them.
B. Administrative: This Service-Type attribute grants full administrative access, including the ability to modify configurations, which is not suitable for read-only access.
C. Call Check: This attribute is used for call verification and is unrelated to WLC management access.
D. Callback Login: This attribute is used for callback authentication and is not relevant for providing read-only access to the WLC.
The Service-Type attribute in RADIUS defines the type of service being provided to the user. For WLC management access, the following values are relevant:
Administrative (6): This value grants administrative access to the WLC. However, the level of access (read-only or read-write) is further controlled by the Privilege Level attribute.
To enforce read-only access, the Privilege Level attribute should be set to 1 (read-only) in conjunction with the Service-Type attribute set to Administrative.
Why not the other options?
A. NAS Prompt: This is not relevant for WLC management access.
The correct answer is:
A. NAS Prompt
Explanation:
In RADIUS, the Service-Type attribute defines the type of service to be provided to the user. For read-only access on a Wireless LAN Controller (WLC), the Service-Type should be set to NAS Prompt. This value typically provides the user with a lower level of access, such as read-only, as opposed to full administrative access, which would be set by using the Administrative service type.
By setting the Service-Type to NAS Prompt, the user is granted read-only access to the WLC, which aligns with the requirement.
Answer is A
https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/71989-manage-wlc-users-radius.html#toc-hId--1799525129
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.300-430 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
rrahim
2 months, 2 weeks agorrahim
2 months, 2 weeks agonetwkguy99
8 months, 2 weeks agoclaudio392
1 year, 2 months agotachy_22
1 year, 4 months agobaddieandyz94
1 year, 4 months ago