nerdexam
HP

HPE6-A84 · Question #10

Refer to the scenario. A customer requires these rights for clients in the "medical-mobile" AOS firewall role on Aruba Mobility Controllers (MCs): - Permitted to receive IP addresses with DHCP…

The correct answer is C. In the "medical-mobile" policy, move rules 6 and 7 to the top of the list. Rules 6 and 7 in the "medical-mobile" policy are used to deny access to the WLAN for a period of time if the clients send any SSH or Telnet traffic, as required by the scenario. However, these rules are currently placed below rule 5, which permits access to the Internet for any…

Troubleshooting Advanced Network Security

Question

Refer to the scenario. A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):

  • Permitted to receive IP addresses with DHCP
  • Permitted access to DNS services from 10.8.9.7 and no other server
  • Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22
  • Denied access to other 10.0.0.0/8 subnets
  • Permitted access to the Internet
  • Denied access to the WLAN for a period of time if they send any SSH traffic
  • Denied access to the WLAN for a period of time if they send any Telnet traffic
  • Denied access to all high-risk websites

External devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic. The exhibits below show the configuration for the role. There are multiple issues with the configuration. What is one of the changes that you must make to the policies to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 8 is “ipv4 any any any permit’.)

Options

  • AIn the "medical-mobile" policy, change the source in rule 1 to "user."
  • BIn the "medical-mobile" policy, change the subnet mask in rule 3 to 255.255.248.0.
  • CIn the "medical-mobile" policy, move rules 6 and 7 to the top of the list.
  • DMove the rule in the "apprf-medical-mobile-sacl" policy between rules 7 and 8 in the "medical-

How the community answered

(54 responses)
  • A
    19% (10)
  • B
    6% (3)
  • C
    67% (36)
  • D
    9% (5)

Explanation

Rules 6 and 7 in the "medical-mobile" policy are used to deny access to the WLAN for a period of time if the clients send any SSH or Telnet traffic, as required by the scenario. However, these rules are currently placed below rule 5, which permits access to the Internet for any traffic. This means that rule 5 will override rules 6 and 7, and the clients will not be denied access to the WLAN even if they send SSH or Telnet traffic. To fix this issue, rules 6 and 7 should be moved to the top of the list, before rule 5. This way, rules 6 and 7 will take precedence over rule 5, and the clients will be denied access to the WLAN if they send SSH or Telnet traffic, as expected.

Topics

#AOS firewall policy#rule ordering#blacklisting#Mobility Controller

Community Discussion

No community discussion yet for this question.

Full HPE6-A84 Practice