nerdexam
HP

HPE6-A78 · Question #81

Refer to the exhibit. A company has an HPE Aruba Networking Instant AP cluster. A Windows 10 client is attempting to connect to a WLAN that enforces WPA3-Enterprise with authentication to HPE Aruba…

The correct answer is B. Whether the client has a valid certificate installed on it to let it support EAP-TLS. The scenario involves an HPE Aruba Networking Instant AP (IAP) cluster with a WLAN configured for WPA3-Enterprise security, using HPE Aruba Networking ClearPass Policy Manager (CPPM) as the authentication server. CPPM is set to require EAP-TLS for authentication. A Windows 10…

Monitoring and Troubleshooting Aruba Network Security

Question

Refer to the exhibit. A company has an HPE Aruba Networking Instant AP cluster. A Windows 10 client is attempting to connect to a WLAN that enforces WPA3-Enterprise with authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is configured to require EAP- TLS. The client authentication fails. In the record for this client's authentication attempt on CPPM, you see this alert. What is one thing that you check to resolve this issue?

Options

  • AWhether EAP-TLS is enabled in the AAA Profile settings for the WLAN on the IAP cluster
  • BWhether the client has a valid certificate installed on it to let it support EAP-TLS
  • CWhether EAP-TLS is enabled in the SSID Profile settings for the WLAN on the IAP cluster
  • DWhether the client has a third-party 802.1X supplicant, as Windows 10 does not support EAP-TLS

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    82% (18)
  • C
    9% (2)
  • D
    5% (1)

Explanation

The scenario involves an HPE Aruba Networking Instant AP (IAP) cluster with a WLAN configured for WPA3-Enterprise security, using HPE Aruba Networking ClearPass Policy Manager (CPPM) as the authentication server. CPPM is set to require EAP-TLS for authentication. A Windows 10 client attempts to connect but fails, and the CPPM Access Tracker shows an error: "Client does not support configured EAP methods," with the error code 9015 under the RADIUS protocol category. EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) is a certificate-based authentication method that requires both the client (supplicant) and the server (CPPM) to present valid certificates during the authentication process. The error message indicates that the client does not support the EAP method configured on CPPM (EAP-TLS), meaning the client is either not configured to use EAP-TLS or lacks the necessary components to perform EAP-TLS authentication.

Topics

#EAP-TLS#client certificate#WPA3-Enterprise#CPPM authentication

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice