HPE6-A78 · Question #72
You have enabled 802.1X authentication on an AOS-CX switch, including on port 1/1/1. That port has these port-access roles configured on it: Fallback role = roleA Auth role = roleB Critical role =…
The correct answer is C. The client receives roleB. In an AOS-CX switch environment, 802.1X authentication is used to authenticate clients connecting to ports, and roles are assigned based on the authentication outcome and configuration. The roles mentioned in the question--fallback, auth, and critical--have specific purposes in…
Question
You have enabled 802.1X authentication on an AOS-CX switch, including on port 1/1/1. That port has these port-access roles configured on it:
Fallback role = roleA Auth role = roleB Critical role = roleC No other port-access roles are configured on the port. A client connects to that port. The user succeeds authentication, and CPPM does not send an Aruba-User-Role VSA. What role does the client receive?
Options
- AThe client receives roleC.
- BThe client is denied access.
- CThe client receives roleB.
- DThe client receives roleA.
How the community answered
(41 responses)- A2% (1)
- B7% (3)
- C78% (32)
- D12% (5)
Explanation
In an AOS-CX switch environment, 802.1X authentication is used to authenticate clients connecting to ports, and roles are assigned based on the authentication outcome and configuration. The roles mentioned in the question--fallback, auth, and critical--have specific purposes in the AOS-CX port- access configuration: Auth role (roleB): This role is applied when a client successfully authenticates via 802.1X and no specific role is assigned by the RADIUS server (e.g., via an Aruba-User-Role VSA). It is the default role for successful authentication. Fallback role (roleA): This role is applied when no authentication method is attempted (e.g., the client does not support 802.1X or MAC authentication and no other method is configured). Critical role (roleC): This role is applied when the switch cannot contact the RADIUS server (e.g., during a server timeout or failure), allowing the client to have limited access in a "critical" state. In this scenario, the client successfully authenticates via 802.1X, and CPPM does not send an Aruba- User-Role VSA. Since authentication is successful, the switch applies the auth role (roleB) as the default role for successful authentication when no specific role is provided by the RADIUS server.
Topics
Community Discussion
No community discussion yet for this question.