HPE6-A78 · Question #65
The first exhibit shows roles on the MC, listed in alphabetic order. The second and third exhibits show the configuration for a WLAN to which a client connects. Which description of the role…
The correct answer is D. A user authenticates successfully with 802.1X, and the RADIUS Access-Accept includes an. In a WLAN setup that uses 802.1X for authentication, the role assigned to a user is determined by the result of the authentication process. When a user successfully authenticates via 802.1X, the RADIUS server may include a Vendor-Specific Attribute (VSA), such as the…
Question
The first exhibit shows roles on the MC, listed in alphabetic order. The second and third exhibits show the configuration for a WLAN to which a client connects. Which description of the role assigned to a user under various circumstances is correct?
Exhibit
Options
- AA user fails 802.1X authentication. The client remains connected, but is assigned the "guest" role.
- BA user authenticates successfully with 802.1 X. and the RADIUS Access-Accept includes an
- CA user authenticates successfully with 802.1X. and the RADIUS Access-Accept includes an
- DA user authenticates successfully with 802.1X, and the RADIUS Access-Accept includes an
How the community answered
(66 responses)- A27% (18)
- B5% (3)
- C11% (7)
- D58% (38)
Explanation
In a WLAN setup that uses 802.1X for authentication, the role assigned to a user is determined by the result of the authentication process. When a user successfully authenticates via 802.1X, the RADIUS server may include a Vendor-Specific Attribute (VSA), such as the Aruba-User-Role, in the Access- Accept message. This attribute specifies the role that should be assigned to the user. If the RADIUS Access-Accept message includes an Aruba-User-Role VSA set to "employee1", the client should be assigned the "employee1" role, as per the VSA, and not the default "guest" role. The "guest" role would typically be a fallback if no other role is specified or if the authentication fails.
Topics
Community Discussion
No community discussion yet for this question.
