QuestionQ41

Authentication/Authorization

A customer has deployed an AOS-10 mobility gateway cluster with three controllers at one site. The WLAN is configured to tunnel wireless-device traffic to the AOS-10 mobility cluster. Clients authenticate through HPE Aruba Networking ClearPass using WPA3-Enterprise (opmode wpa3-aes-ccm-128). The security team requires the ability to force a wireless device to reauthenticate through ClearPass.

Which steps are necessary to ensure that ClearPass can reliably initiate a change of authorization to an AOS-10 mobility cluster, including during gateway failover events?

Choose two
Explanation

RADIUS Change of Authorization in an AOS-10 gateway cluster relies on VRRP virtual IP addresses so ClearPass can send CoA to the current cluster conductor after a gateway or user-designated gateway changes. Manual cluster configuration enables the required cluster and VRRP settings, while Dynamic Authorization (CoA) enables the CoA handling and forwarding needed to prevent requests from being dropped during load balancing or failover. HPE Aruba Networking: Dynamic authorization in a cluster

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!