Configuring IEEE 802.1X Flexible Authentication for Layer 3

Configure network access control mechanisms such as 802.1X and MAB with Cisco Identity Services Engine
Answer Correct answer: D — Configure WebAuth so the hosts are redirected to a web page for authentication.

Which action configures the iEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?

  1. Modify the Dot1x configuration on the VPN server to send Layer 3 authentications to an external authentication database.
  2. Identify the devices using this feature and create a policy that allows them to pass Layer 2 authentication.
  3. Add MAB into the switch to allow redirection to a Layer 3 device for authentication.
  4. Configure WebAuth so the hosts are redirected to a web page for authentication. Correct Answer

Community Votes

D
75%
C
25%

75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept tested is identifying which authentication method within the 802.1X framework operates at Layer 3 versus Layer 2.

This question explores the configuration of IEEE 802.1X Flexible Authentication methods, specifically distinguishing between Layer 2 and Layer 3 mechanisms to identify the correct action for Layer 3 support.

Many learners select MAC Authentication Bypass (MAB) because it acts as a fallback mechanism, but MAB itself is fundamentally a Layer 2 authentication method based on hardware addresses.

Community Discussion (3 comments)

madboy2 👍 1 Selected: C
The IEEE 802.1X Flexible Authentication feature allows for Layer 3 authentication mechanisms (such as web-based or other IP-based mechanisms) in addition to the standard Layer 2 authentication. By configuring MAC Authentication Bypass (MAB), devices that cannot support 802.1X can be redirected to Layer 3 authentication methods such as web authentication or other external methods. 🔹 MAB is used to redirect devices to a Layer 3 device (like a web server or a different authentication service) for authentication when 802.1X authentication fails (or when the device cannot perform Layer 2 authentication). This action is especially useful when integrating non-802.1X-capable devices into a secure network environment where they must be authenticated using Layer 3 mechanisms.
KnightHeart 👍 3 Selected: D
Only D is layer 3
klu16 👍 2
A & C are Layer 2. IEEE 802.1X Flexible Authentication Methods The IEEE 802.1X Flexible Authentication feature supports three authentication methods: dot1X--IEEE 802.1X authentication is a Layer 2 authentication method. mab--MAC-Authentication Bypass is a Layer 2 authentication method. webauth--Web authentication is a Layer 3 authentication method. So, it's D imo.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

IEEE 802.1X Flexible Authentication supports three distinct methods: dot1x, mab, and webauth. WebAuth is explicitly defined as a Layer 3 authentication method because it relies on IP connectivity to redirect users to a web portal for credentials. Configuring WebAuth allows the switch to authenticate hosts that cannot perform standard 802.1X exchanges by using HTTP/HTTPS redirection.

Why the Other Options Are Wrong

Option A refers to VPN server configurations which are not part of the local switch's 802.1X flexible authentication feature set. Option B describes policy creation rather than the specific authentication mechanism configuration. Option C suggests adding MAC Authentication Bypass (MAB), which is incorrect because MAB authenticates devices based on their MAC address at Layer 2, not Layer 3.

Community Comment Notes

Community consensus strongly favors WebAuth. As noted by user klu16, "A & C are Layer 2... webauth--Web authentication is a Layer 3 authentication method." User KnightHeart also reinforced this by stating simply, "Only D is layer 3," highlighting the fundamental distinction between the protocols.

Exam Strategy

When studying 802.1X, memorize the three supported methods: dot1x (Layer 2), mab (Layer 2), and webauth (Layer 3). Exam questions often ask you to differentiate these based on the OSI layer or the type of credential used.

Frequently Asked Questions

Is MAB a Layer 2 or Layer 3 authentication?

MAB is a Layer 2 authentication method. It authenticates devices based on their MAC address before any Layer 3 IP communication is established.

Why is WebAuth considered Layer 3 in 802.1X?

WebAuth requires the host to have an IP address and be able to send HTTP/HTTPS requests to a captive portal, which are Layer 3 and Layer 4 functions.

Related Analysis

← Back to 350-701 Study Guide