HPE6-A84 · Question #3
Refer to the scenario. A customer requires these rights for clients in the "medical-mobile" AOS firewall role on Aruba Mobility Controllers (MCs): - Permitted to receive IP addresses with DHCP…
The correct answer is B. In the "medical-mobile" policy, change the subnet mask in rule 3 to 255.255.248.0. The subnet mask in rule 3 of the "medical-mobile" policy is currently 255.255.252.0, which means that the rule denies access to the 10.1.12.0/22 subnet as well as the adjacent 10.1.16.0/22 subnet. This is not consistent with the scenario requirements, which state that only the…
Question
Refer to the scenario. A customer requires these rights for clients in the "medical-mobile" AOS firewall role on Aruba Mobility Controllers (MCs):
- Permitted to receive IP addresses with DHCP
- Permitted access to DNS services from 10.8.9.7 and no other server
- Permitted access to all subnets in the 10.1.0.0/16 range except
denied access to 10.1.12.0/22
- Denied access to other 10.0.0.0/8 subnets
- Permitted access to the Internet
- Denied access to the WLAN for a period of time if they send any SSH
traffic
- Denied access to the WLAN for a period of time if they send any
Telnet traffic
- Denied access to all high-risk websites
External devices should not be permitted to initiate sessions with "medical-mobile" clients, only send return traffic. The exhibits below show the configuration for the role. There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, "medical-mobile" rule 1 is "ipv4 any any svc-dhcp permit," and rule 8 is "ipv4 any any any permit".)
Exhibit
Options
- AIn the "medical-mobile" policy, move rules 2 and 3 between rules 7 and 8.
- BIn the "medical-mobile" policy, change the subnet mask in rule 3 to 255.255.248.0.
- CMove the rule in the "apprf-medical-mobile-sacl" policy between rules 7 and 8 in the "medical-
- DIn the "medical-mobile" policy, change the source in rule 8 to "user."
How the community answered
(34 responses)- A24% (8)
- B59% (20)
- C12% (4)
- D6% (2)
Explanation
The subnet mask in rule 3 of the "medical-mobile" policy is currently 255.255.252.0, which means that the rule denies access to the 10.1.12.0/22 subnet as well as the adjacent 10.1.16.0/22 subnet. This is not consistent with the scenario requirements, which state that only the 10.1.12.0/22 subnet should be denied access, while the rest of the 10.1.0.0/16 range should be permitted access. To fix this issue, the subnet mask in rule 3 should be changed to 255.255.248.0, which means that the rule only denies access to the 10.1.8.0/21 subnet, which includes the 10.1.12.0/22 subnet. This way, the rule matches the scenario requirements more
Topics
Community Discussion
No community discussion yet for this question.
