An administrator needs to connect ISE to Active Directory as an external authentication source and allow the proper ports through the firewall. Which two ports should be opened to accomplish this task? (Choose two.)
DE is still valid on ISE 3.0 , there is however several other ports based on the context of the question as seen on this document.
https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_7.html
page 5 at Cisco document clearly answers the question:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_20.pdf
The two ports that should be opened to connect ISE to Active Directory as an external authentication source are LDAP: 389 and HTTPS: 443.
LDAP (Lightweight Directory Access Protocol) is a protocol for accessing directory services, such as Active Directory. ISE uses LDAP to authenticate users against Active Directory.
HTTPS (Hypertext Transfer Protocol Secure) is a secure version of HTTP that uses Transport Layer Security (TLS) to encrypt traffic between ISE and Active Directory.
The other ports are not required for this task.
TELNET: 23 is a text-based protocol that is not secure.
HTTP: 80 is a protocol for accessing web pages. It is not secure by default, but it can be secured using HTTPS.
MSRPC (Microsoft Remote Procedure Call) is a protocol for remote procedure calls. It is not required for connecting ISE to Active Directory.
The provided answer is correct. These are the important ports to open in AD implementation:
https://cloudinfrastructureservices.co.uk/active-directory-ports/
This section is not available anymore. Please use the main Exam Page.300-715 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
[Removed]
11 months agofaridh
1 year, 3 months agodenverfly
1 year, 5 months agoTHEODORABLE
1 year, 6 months agoIlPerdan0
1 year, 11 months agokingsalah1982
2 years ago