HPE6-A84 · Question #16
A customer requires a secure solution for connecting remote users to the corporate main site. You are designing a client-to-site virtual private network (VPN) based on Aruba VIA and Aruba Mobility…
The correct answer is A. Set up the VPNCs' VIA web authentication profile to use CPPM as the authentication server; set. The VIA web authentication profile is used to authenticate the users who want to download the VIA connection settings from the VPNCs. The VPNCs can use either an internal database or an external server (such as RADIUS or LDAP) as the authentication source for this profile. To…
Question
A customer requires a secure solution for connecting remote users to the corporate main site. You are designing a client-to-site virtual private network (VPN) based on Aruba VIA and Aruba Mobility Controllers acting as VPN Concentrators (VPNCs). Remote users will first use the VIA client to contact the VPNCs and obtain connection settings. The users should only be allowed to receive the settings if they are the customer's "RemoteEmployees" AD group. After receiving the settings, the VIA clients will automatically establish VPN connections, authenticating to CPPM with certificates. What should you do to help ensure that only authorized users obtain VIA connection settings?
Options
- ASet up the VPNCs' VIA web authentication profile to use CPPM as the authentication server; set
- BSet up the VPNCs' VIA web authentication profile to use an AD domain controller as the LDAP
- CSet up the VPNCs' VIA connection profile to use two authentication profiles, one RADIUS profile to
- DSet up the VPNCs' VIA connection profile to use one authentication profile, which is set to the AD
How the community answered
(19 responses)- A63% (12)
- B11% (2)
- C21% (4)
- D5% (1)
Explanation
The VIA web authentication profile is used to authenticate the users who want to download the VIA connection settings from the VPNCs. The VPNCs can use either an internal database or an external server (such as RADIUS or LDAP) as the authentication source for this profile. To ensure that only authorized users obtain VIA connection settings, you should use CPPM as the external server and configure a service on CPPM that uses AD as the authentication source. This way, you can leverage the role mapping and enforcement features of CPPM to check if the users belong to the "RemoteEmployees" AD group and grant or deny them access accordingly.
Topics
Community Discussion
No community discussion yet for this question.