HPE6-A71 · Question #34
Refer to the exhibit. An administrator implements an L2 cluster of Aruba Mobility Controllers (MCs) as shown in the exhibit. An external RADUIS AAA server authenticates clients associated with the…
The correct answer is B. The user's session remains active, but the AAA server cannot implement RADIUS Change of. "The Authorization module authenticates clients on the A-UAC and sets the A-UAC IP address as the NAS-IP. External RADIUS servers set the NAS-IP as the A-UAC IP in the client database (Figure 6-17). This NAS-IP is used later to change client states or attributes. However, when…
Question
Refer to the exhibit. An administrator implements an L2 cluster of Aruba Mobility Controllers (MCs) as shown in the exhibit. An external RADUIS AAA server authenticates clients associated with the Active User Anchor Controller (A-UAC), where the NAS IP address sent from Controller B is 10.254.1.2. By default, what happens to the user's session when it is handed over to the Standby UAC (S- UAC) after a failover?
Exhibit
Options
- AThe user's session remains active and RADIUS messages can still be processed between the
- BThe user's session remains active, but the AAA server cannot implement RADIUS Change of
- CThe user's session is disconnected and has to reconnect, and no record of this process is
- DThe user's session is disconnected and has to reconnect, but the S-UAC automatically
How the community answered
(25 responses)- A16% (4)
- B72% (18)
- C8% (2)
- D4% (1)
Explanation
"The Authorization module authenticates clients on the A-UAC and sets the A-UAC IP address as the NAS-IP. External RADIUS servers set the NAS-IP as the A-UAC IP in the client database (Figure 6-17). This NAS-IP is used later to change client states or attributes. However, when the client moves to a new UAC, the authentication server is not updated. This means that transactions initiated by the authorization server will fail. To resolve this issue, you should configure each cluster member to use the Virtual Router Redundancy Protocol (VRRP), as described below. This enables interaction between the cluster and the authorization server. "
Topics
Community Discussion
No community discussion yet for this question.
