Wired 802.1X Monitor Mode Command for Minimal Impact
An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests IBNS 2.0 monitor mode configuration; the common trap is confusing the descriptive feature name 'monitor mode' with the actual CLI command.
This guide explains how to configure Cisco wired 802.1X monitor mode to log failed authentications in ISE without impacting users. It confirms the 'authentication open' command as the correct configuration.
Choosing 'monitor-mode enabled' (Option A) because it matches the feature name, but the actual valid interface command is 'authentication open'.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Theauthentication open command configures a switch port for monitor mode (also known as open mode or low-impact mode). In this state, if 802.1X authentication fails and ISE sends an Access-Reject, the switch logs the failure in ISE but still allows the endpoint traffic to pass. This ensures minimal impact on users during a new deployment while allowing administrators to tune their policies.Why the Other Options Are Wrong
Option A,monitor-mode enabled, is a distractor that sounds like the feature name but is not a valid Cisco IOS interface command. Option B, authentication host-mode multi-auth, dictates how multiple devices on a single port are authenticated but does not control the port's behavior upon authentication failure. Option D, pae dot1x enabled, simply enables the 802.1X authenticator role on the port but does not configure open/monitor mode behavior.Community Comment Notes
Commenters correctly identified that theauthentication open command allows traffic to pass even upon receiving an Access-Reject from ISE, which is the essence of monitor mode. As TiberiuszSun noted, "even if ISE sends back a deny... the switch will ignore that and still allow traffic to pass." Others emphasized that the question specifically asks for a "command," which helps eliminate distractors that are not valid CLI syntax. Official Reference
Exam Strategy
When a question asks for a specific command to implement a feature, focus on exact CLI syntax rather than descriptive feature names. For 802.1X monitor mode, remember that 'authentication open' is the required interface command, not variations like 'monitor-mode'.