nerdexam
HP

HPE6-A78 · Question #109

How does the AOS firewall determine which rules to apply to a specific client's traffic?

The correct answer is A. The firewall applies the rules in policies associated with the client's user role. In an AOS-8 architecture, the Mobility Controller (MC) includes a stateful firewall that enforces policies on client traffic. The firewall uses user roles to apply policies, allowing granular control over traffic based on the client's identity and context. User Roles: In AOS-8…

Aruba Security Solutions and Architectures

Question

How does the AOS firewall determine which rules to apply to a specific client's traffic?

Options

  • AThe firewall applies the rules in policies associated with the client's user role.
  • BThe firewall applies every rule that includes the client's IP address as the source.
  • CThe firewall applies the rules in policies associated with the client's WLAN.
  • DThe firewall applies every rule that includes the client's IP address as the source or destination.

How the community answered

(47 responses)
  • A
    94% (44)
  • B
    4% (2)
  • D
    2% (1)

Explanation

In an AOS-8 architecture, the Mobility Controller (MC) includes a stateful firewall that enforces policies on client traffic. The firewall uses user roles to apply policies, allowing granular control over traffic based on the client's identity and context. User Roles: In AOS-8, each client is assigned a user role after authentication (e.g., via 802.1X, MAC authentication, or captive portal). The user role contains firewall policies (rules) that define what traffic is allowed or denied for clients in that role. For example, a "guest" role might allow only HTTP/HTTPS traffic, while an "employee" role might allow broader access. Option A, "The firewall applies the rules in policies associated with the client's user role," is correct. The AOS firewall evaluates traffic based on the user role assigned to the client. Each role has a set of policies (rules) that are applied in order, and the first matching rule determines the action (permit or deny). For example, if a client is in the "employee" role, the firewall applies the rules defined in the "employee" role's policy.

Topics

#AOS firewall#user role#firewall policy#role-based access

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice