QuestionQ8

Protect and Defend

Refer to the scenario.

A customer has AOS-CX switches with this configuration on their edge ports: port-access onboarding-method concurrent enable aaa authentication port-access mac-auth enable quiet-period 60 aaa authentication port-access dotx1 authenticator enable

The switch authenticates clients to HPE Aruba Networking ClearPass Policy Manager (CPPM), which has these services:

  1. An 802.1X service that uses an EAP-TLS method for most clients
  2. A MAC-Auth service that uses the [MAC-Auth] method for devices such as printers imported from an inventory manager

The customer now wants to give limited access to wired guest devices and new devices that must be enrolled with certificates. You have configured these rights in an AOS-CX role named "guest-login."

How should the "guest-login" role be applied on the switches?

Question Image

Question Image

  • A As the role assigned by the default enforcement profile in CPPM's MAC-Auth service
  • B As the port-access preauth-role on the edge interfaces
  • C As the port-access reject-role on the edge interfaces
  • D As the role assigned by the default enforcement profile in CPPM's 802.1X service
Explanation

With concurrent onboarding enabled, AOS-CX keeps a client in the pre-authentication role while 802.1X and MAC authentication are in progress. Assigning guest-login as the port-access preauth-role provides the limited connectivity needed for guests and certificate-enrollment devices before authentication succeeds. A reject role is used only when authentication fails.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!