H12-725_V4.0 · Question #73
Huawei iMaster NCE-Campus can be used as an authentication server to authorize authenticated users. Which of the following is not an authorizable parameter of iMaster NCE-Campus?
The correct answer is D. IP address. IP address (D) is the correct answer because iMaster NCE-Campus, acting as an authentication/authorization server, pushes network policy parameters to network devices - it does not assign IP addresses. IP address allocation is the responsibility of a DHCP server, which is a…
Question
Huawei iMaster NCE-Campus can be used as an authentication server to authorize authenticated users. Which of the following is not an authorizable parameter of iMaster NCE-Campus?
Options
- AACL
- BVLAN
- CDSCP
- DIP address
How the community answered
(58 responses)- A2% (1)
- B10% (6)
- C5% (3)
- D83% (48)
Explanation
IP address (D) is the correct answer because iMaster NCE-Campus, acting as an authentication/authorization server, pushes network policy parameters to network devices - it does not assign IP addresses. IP address allocation is the responsibility of a DHCP server, which is a separate function entirely outside the scope of 802.1X or MAC-based authorization policies.
ACL (A), VLAN (B), and DSCP (C) are all valid authorizable parameters: after a user authenticates, iMaster NCE-Campus can instruct the access device to apply a specific ACL to control traffic permissions, place the user into a designated VLAN for network segmentation, and mark packets with a DSCP value for QoS treatment - all of which are policy attributes pushed to the switch or AP.
Memory tip: Think of authorization parameters as post-login network policies applied by the switch. A switch can enforce ACLs, VLANs, and DSCP markings on a port, but it cannot hand out an IP address - that requires a DHCP handshake. If a parameter belongs to DHCP's job, it's not an authorization parameter.
Topics
Community Discussion
No community discussion yet for this question.