HPE6-A84 · Question #14
Refer to the scenario. A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM). Switches are using local…
The correct answer is B. port-access role internet-only gateway-zone zone myzone gateway-role eth-internet. The UBT solution requires that the edge ports on the switches are configured in VLAN trunk mode, not access mode. This is because the UBT solution uses a special VLAN (VLAN 4095 by default) to encapsulate the user traffic and tunnel it to the gateway. The edge ports need to…
Question
Refer to the scenario. A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM). Switches are using local port-access policies. The customer wants to start tunneling wired clients that pass user authentication only to an Aruba gateway cluster. The gateway cluster should assign these clients to the "eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20. The plan for the enforcement policy and profiles is shown below:
The gateway cluster has two gateways with these IP addresses:
- Gateway 1
o VLAN 4085 (system IP) = 10.20.4.21 o VLAN 20 (users) = 10.20.20.1 o VLAN 4094 (WAN) = 198.51.100.14
- Gateway 2
o VLAN 4085 (system IP) = 10.20.4.22 o VLAN 20 (users) = 10.20.20.2 o VLAN 4094 (WAN) = 198.51.100.12
- VRRP on VLAN 20 = 10.20.20.254
The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster. Assume that you are using the "myzone" name for the UBT zone. Which is a valid minimal configuration for the AOS-CX port-access roles?
Options
- Aport-access role eth-internet gateway-zone zone myzone gateway-role eth-user
- Bport-access role internet-only gateway-zone zone myzone gateway-role eth-internet
- Cport-access role eth-internet gateway-zone zone myzone gateway-role eth-internet vlan access 20
- Dport-access role internet-only gateway-zone zone myzone gateway-role eth-internet vlan access
How the community answered
(40 responses)- A8% (3)
- B75% (30)
- C3% (1)
- D15% (6)
Explanation
The UBT solution requires that the edge ports on the switches are configured in VLAN trunk mode, not access mode. This is because the UBT solution uses a special VLAN (VLAN 4095 by default) to encapsulate the user traffic and tunnel it to the gateway. The edge ports need to allow this VLAN as well as any other VLANs that are used for management or control traffic. Therefore, the edge ports should be configured as VLAN trunk ports and allow the necessary VLANs.
Topics
Community Discussion
No community discussion yet for this question.