nerdexam
HP

HPE6-A78 · Question #47

You have a network with ArubaOS-Switches for which Aruba ClearPass Policy Manager (CPPM) is acting as a TACACS+ server to authenticate managers. CPPM assigns the admins a TACACS+ privilege level…

The correct answer is D. This approach will work to assign admins to the default "administrators" group, but not to the. With ArubaOS-CX switches, the use of ClearPass Policy Manager (CPPM) as a TACACS+ server for authentication is supported. The privilege levels assigned by CPPM will translate onto the switches, where the "manager" privilege level typically maps to administrative capabilities…

Implementing and Configuring Aruba Network Security

Question

You have a network with ArubaOS-Switches for which Aruba ClearPass Policy Manager (CPPM) is acting as a TACACS+ server to authenticate managers. CPPM assigns the admins a TACACS+ privilege level, either manager or operator. You are now adding ArubaOS-CX switches to the network. ClearPass admins want to use the same CPPM service and policies to authenticate managers on the new switches. What should you explain?

Options

  • AThis approach cannot work because the ArubaOS-CX switches do not accept standard TACACS+
  • BThis approach cannot work because the ArubaOS-CX switches do not support TACACS+.
  • CThis approach will work, but will need to be adjusted later if you want to assign managers to the
  • DThis approach will work to assign admins to the default "administrators" group, but not to the

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    7% (2)
  • C
    3% (1)
  • D
    76% (22)

Explanation

With ArubaOS-CX switches, the use of ClearPass Policy Manager (CPPM) as a TACACS+ server for authentication is supported. The privilege levels assigned by CPPM will translate onto the switches, where the "manager" privilege level typically maps to administrative capabilities and the "operator" privilege level maps to more limited capabilities. ArubaOS-CX does support standard TACACS+ privilege levels, so administrators can be assigned appropriately. If the ClearPass policies are correctly configured, they will work for both ArubaOS-Switches and ArubaOS-CX switches. The distinction between the "administrators" and "operators" groups is inherent in the ArubaOS-CX role- based access control, and these default groups need to be appropriately mapped to the TACACS+ privilege levels assigned by CPPM.

Topics

#TACACS+#ArubaOS-CX#ClearPass#admin authentication

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice