What WebAuth Type is Used for AUP Acceptance and MAC Registration?

Configure web authentication Configure guest access services
Answer Correct answer: D — The administrator must configure device registration WebAuth to present an AUP and register the unknown MAC address.

A network security administrator needs a web authentication configuration when a guest user connects to the network with a wireless connection using these steps: • An initial MAB request is sent to the Cisco ISE node. • Cisco ISE responds with a URL redirection authorization profile if the user's MAC address is unknown in the endpoint identity store. • The URL redirection presents the user with an AUP acceptance page when the user attempts to go to any URL. Which authentication must the administrator configure on Cisco ISE?

  1. wired NAD with local WebAuth
  2. WLC with local WebAuth
  3. NAD with central WebAuth
  4. device registration WebAuth Correct Answer

Community Votes

D
67%
C
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between Central Web Auth and Device Registration WebAuth, where an AUP acceptance page registering the MAC address indicates the Hotspot portal (Device Registration WebAuth).

This scenario tests configuring web authentication for guest access when an unknown MAC address triggers an AUP acceptance page. The page establishes that Device Registration WebAuth is the required authorization profile for this Hotspot portal flow.

Choosing C (Central Web Auth) because it is the most common redirect type for ISE guest portals, missing that AUP-only Hotspot portals use Device Registration WebAuth to register the MAC address.

Community Discussion (4 comments)

Cachaman 👍 1 Selected: D
I take that back, correct answer D, below why. Self registration and sponsored portal use ---> Central web authentication (C is correct) Hotspot uses Device registration WebAuth (D is correct). The Key here is "URL redirection presents an AUP" ---> Hotspot The Hotspot Guest portal is an alternative Guest portal that allows you to provide network access without requiring guests to have usernames and passwords and alleviates the need to manage guest accounts. Instead, Cisco ISE works together with the network access device (NAD) and Device Registration Web Authentication (Device Registration WebAuth) to grant network access directly to the guest devices. https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_guest.html
Cachaman 👍 1 Selected: C
Correct C Step 5. Select the Web Redirection checkbox and choose Centralized Web Auth from the first dropdown. In the ACL text box, type ACL-WEBAUTH-REDIRECT. You are using a default WebAuth portal, so ensure that Sponsored Guest Portal (default) is selected from the Value dropdown. https://www.ciscopress.com/articles/article.asp?p=3100059&seqNum=3
one_1996 👍 1 Selected: C
D. Device registration WebAuth → This method is used for device onboarding, not for guest authentication.
An312 👍 3 Selected: D
Device Registration WebAuth: In this scenario, the guest user connects to the network with a wireless connection. An initial MAC authentication bypass (MAB) request is sent to the Cisco ISE node. If the user MAC address is not in the endpoint identity store, Cisco ISE responds with a URL redirection authorization profile. The URL redirection presents the user with an AUP acceptance page when the user attempts to go to any URL.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Device Registration WebAuth (DRW) is the correct authorization profile type for Hotspot guest portals in Cisco ISE. When an unknown MAC address performs MAB, ISE redirects the user to a Hotspot portal to accept the Acceptable Use Policy (AUP). Upon acceptance, ISE automatically registers the endpoint's MAC address in the endpoint identity store, which perfectly matches the described flow.

Why the Other Options Are Wrong

Option C (NAD with central WebAuth) is incorrect because Central Web Auth is used for Sponsored and Self-Registration portals where users provide credentials, not merely accept an AUP to register their MAC. Options A and B (Local WebAuth) are incorrect because Local WebAuth hosts the portal on the Network Access Device (NAD) or WLC, whereas this scenario relies on ISE for the redirection and identity store lookup.

Community Comment Notes

Commenters highlighted the key distinction between portal types, noting that "Self registration and sponsored portal use ---> Central web authentication" while "Hotspot uses Device registration WebAuth". As another user pointed out, the critical clue is the AUP acceptance, which signals a Hotspot portal requiring device registration rather than full credential authentication.

Official Reference

Exam Strategy

Identify the portal type based on the user interaction: if the user only accepts an AUP and the MAC is registered, it is a Hotspot portal using Device Registration WebAuth. If the user must enter credentials, it is a Sponsored or Self-Registration portal using Central Web Auth.

Related Analysis

← Back to 300-715 Study Guide