nerdexam
HP

HPE6-A78 · Question #99

A company has an AOS controller-based solution with a WPA3-Enterprise WLAN, which authenticates wireless clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). The company has decided to…

The correct answer is C. The Alerts tab in the authentication record in CPPM Access Tracker. The scenario involves an AOS-8 controller-based solution with a WPA3-Enterprise WLAN using HPE Aruba Networking ClearPass Policy Manager (CPPM) for authentication. The company is using digital certificates for authentication (likely EAP-TLS, as it's the most common certificate…

Monitoring and Troubleshooting Aruba Network Security

Question

A company has an AOS controller-based solution with a WPA3-Enterprise WLAN, which authenticates wireless clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). The company has decided to use digital certificates for authentication. A user's Windows domain computer has had certificates installed on it. However, the Networks and Connections window shows that authentication has failed for the user. The Mobility Controller's (MC's) RADIUS events show that it is receiving Access-Rejects for the authentication attempt. What is one place that you can look for deeper insight into why this authentication attempt is failing?

Options

  • AThe reports generated by HPE Aruba Networking ClearPass Insight
  • BThe RADIUS events within the CPPM Event Viewer
  • CThe Alerts tab in the authentication record in CPPM Access Tracker
  • DThe packets captured on the MC control plane destined to UDP 1812

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    5% (2)
  • C
    76% (29)
  • D
    13% (5)

Explanation

The scenario involves an AOS-8 controller-based solution with a WPA3-Enterprise WLAN using HPE Aruba Networking ClearPass Policy Manager (CPPM) for authentication. The company is using digital certificates for authentication (likely EAP-TLS, as it's the most common certificate- based method for WPA3-Enterprise). A user's Windows domain computer has certificates installed, but authentication fails. The Mobility Controller (MC) logs show Access-Rejects from CPPM, indicating that CPPM rejected the authentication attempt. Access-Reject: An Access-Reject message from CPPM means that the authentication failed due to a policy violation, certificate issue, or other configuration mismatch. To troubleshoot, we need to find detailed information about why CPPM rejected the request. Option C, "The Alerts tab in the authentication record in CPPM Access Tracker," is correct. Access Tracker in CPPM logs all authentication attempts, including successful and failed ones. For a failed attempt (Access- Reject), the authentication record in Access Tracker will include an Alerts tab that provides detailed reasons for the failure. For example, if the client's certificate is invalid (e.g., expired, not trusted, or missing a required attribute), or if the user does not match a policy in CPPM, the Alerts tab will specify the exact issue (e.g., "Certificate not trusted," "User not found in directory").

Topics

#EAP-TLS#CPPM Access Tracker#RADIUS Access-Reject#certificate authentication

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice