After changing the ISE guest portal URL to a static FQDN, users see certificate errors. Which two steps are required to implement the FQDN correctly? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Add a DNS record resolving the FQDN to the PSN IP address, Create and sign a CSR that includes the static FQDN.
Why this is the answer
When changing the ISE guest portal URL to a static FQDN, two critical steps are needed to prevent certificate errors. First, you must add a DNS record that resolves the new FQDN to the IP address of the Policy Service Node (PSN) hosting the guest portal. This ensures client devices can find the portal using the FQDN. Second, you need to create a Certificate Signing Request (CSR) on the PSN that includes this new static FQDN as a Subject Alternative Name (SAN) or Common Name (CN). This CSR is then signed by a trusted Certificate Authority (CA), and the resulting certificate is installed on the PSN. This ensures the certificate presented by the PSN matches the FQDN clients are trying to reach, thus avoiding certificate warnings. Manually editing host files is impractical for large deployments. Disabling HTTPS on the WLC is insecure and unrelated to the guest portal certificate. Adding the FQDN to the WLC virtual interface is not where the guest portal certificate is managed.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed