nerdexam
HP

HPE6-A84 · Question #6

Refer to the scenario. A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM). Switches are using local…

The correct answer is B. Create a new VLAN on the AOS-CX switch and configure that VLAN as the UBT client VLAN. The correct answer is B. Create a new VLAN on the AOS-CX switch and configure that VLAN as the UBT client VLAN. User-based tunneling (UBT) is a feature that allows the AOS-CX switches to tunnel the traffic from wired clients to a mobility gateway cluster, where they can be…

Implementing and Integrating Advanced Network Security

Question

Refer to the scenario. A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM). Switches are using local port-access policies. The customer wants to start tunneling wired clients that pass user authentication only to an Aruba gateway cluster. The gateway cluster should assign these clients to the "eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20. The plan for the enforcement policy and profiles is shown below:

The gateway cluster has two gateways with these IP addresses:

  • Gateway 1

o VLAN 4085 (system IP) = 10.20.4.21 o VLAN 20 (users) = 10.20.20.1 o VLAN 4094 (WAN) = 198.51.100.14

  • Gateway 2

o VLAN 4085 (system IP) = 10.20.4.22 o VLAN 20 (users) = 10.20.20.2 o VLAN 4094 (WAN) = 198.51.100.12

  • VRRP on VLAN 20 = 10.20.20.254

The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster. Assume that you have configured the correct UBT zone and port-access role settings. However, the solution is not working. What else should you make sure to do?

Options

  • AAssign VLAN 20 as the access VLAN on any edge ports to which tunneled clients might connect.
  • BCreate a new VLAN on the AOS-CX switch and configure that VLAN as the UBT client VLAN.
  • CAssign sufficient VIA licenses to the gateways based on the number of wired clients that will
  • DChange the port-access auth-mode mode to client-mode on any edge ports to which tunneled

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    77% (23)
  • C
    7% (2)
  • D
    13% (4)

Explanation

The correct answer is B. Create a new VLAN on the AOS-CX switch and configure that VLAN as the UBT client VLAN. User-based tunneling (UBT) is a feature that allows the AOS-CX switches to tunnel the traffic from wired clients to a mobility gateway cluster, where they can be assigned a role and a VLAN based on their authentication and authorization. To enable UBT, the switches need to have a UBT zone configured with the IP addresses of the gateways, and a UBT client VLAN configured with the ubt- client-vlan command. The UBT client VLAN is a special VLAN that is used to encapsulate the traffic from the tunneled clients before sending it to the gateways. The UBT client VLAN must be different from any other VLANs used on the switch or the network, and it must not be assigned to any ports or interfaces on the switch. The UBT client VLAN is only used internally by the switch for UBT, and it is not visible to the clients or the gateways. In this scenario, the customer wants to tunnel the clients that pass user authentication to the gateway cluster, where they will be assigned to VLAN 20. Therefore, the switch must have a UBT client VLAN configured that is different from VLAN 20 or any other VLANs on the network. For example, the switch can use VLAN 4000 as the UBT client VLAN, as shown in one of the web search results. The switch must also have a UBT zone configured with the system IP addresses of the gateways as the primary and backup controllers, as explained in question.

Topics

#UBT#AOS-CX#VLAN configuration#gateway tunneling

Community Discussion

No community discussion yet for this question.

Full HPE6-A84 Practice