HPE6-A78 · Question #110
Refer to the exhibits. An admin has created a WLAN that uses the settings shown in the exhibits (and has not otherwise adjusted the settings in the AAA profile). A client connects to the WLAN. Under…
The correct answer is B. The client has passed 802.1X authentication, and the authentication server did not send an Aruba-. The exhibit shows the configuration of a WLAN on an AOS-8 Mobility Controller (MC) with the following settings: Key management: WPA3-Enterprise (indicating 802.1X authentication). Use CNSA suite: Unchecked (using standard encryption, not the Commercial National Security…
Question
Refer to the exhibits. An admin has created a WLAN that uses the settings shown in the exhibits (and has not otherwise adjusted the settings in the AAA profile). A client connects to the WLAN. Under which circumstances will a client receive the default role assignment?
Exhibit
Options
- AThe client has attempted 802.1X authentication, but the MC could not contact the authentication
- BThe client has passed 802.1X authentication, and the authentication server did not send an Aruba-
- CThe client has attempted 802.1X authentication, but failed to maintain a reliable connection,
- DThe client has passed 802.1X authentication, and the value in the Aruba-User-Role VSA matches
How the community answered
(41 responses)- A10% (4)
- B80% (33)
- C2% (1)
- D7% (3)
Explanation
The exhibit shows the configuration of a WLAN on an AOS-8 Mobility Controller (MC) with the following settings: Key management: WPA3-Enterprise (indicating 802.1X authentication). Use CNSA suite: Unchecked (using standard encryption, not the Commercial National Security Algorithm suite). Key size: 128 bits (standard for AES-GCMP in WPA3). Reauth interval: 1440 minutes (24 hours, the interval for re-authentication). Machine authentication: Disabled (only user authentication is required). Blacklisting: Disabled (clients are not blacklisted after failed attempts). The question states that the AAA profile settings have not been adjusted, meaning the default roles (e.g., initial role, logon role, 802.1X default role) are not specified in the exhibit and are assumed to be the system defaults (e.g., "logon" for the initial and logon roles, and a default role like "guest" for the 802.1X default role). The question asks under which circumstances a client will receive the "default role assignment," which refers to the 802.1X default role configured in the AAA profile for the WLAN. 802.1X Authentication Process in AOS-8: When a client connects to a WPA3-Enterprise WLAN, it starts in the initial role (typically "logon") to allow basic connectivity (e.g., DHCP, DNS). During 802.1X authentication, the client is placed in the logon role to allow communication with the authentication server (e.g., ClearPass Policy Manager, CPPM). If authentication succeeds, the client is assigned a role: If the authentication server (e.g., CPPM) sends an Aruba-User-Role VSA with a role that exists on the MC, the client is assigned that role. If no Aruba-User-Role VSA is sent, the client is assigned the 802.1X default role configured in the AAA profile for the WLAN. If authentication fails or the server is unreachable, the client may be assigned a different role (e.g., a critical role, if configured) or denied access.
Topics
Community Discussion
No community discussion yet for this question.
