HPE7-A01 · Question #125
A company with 10,281 employees recently deployed new HPE Aruba Networking Access Points at different branch offices. Wireless 802.IX authentication will be against a RADIUS server in the cloud. The…
The correct answer is B. Configure RedSec on the AP and the RADIUS server. RadSec (RADIUS Security, styled "RedSec" in this question) wraps RADIUS traffic in TLS, directly encrypting the authentication messages traveling between the AP and the cloud RADIUS server - this precisely addresses the security team's concern about exposed RADIUS traffic in…
Question
A company with 10,281 employees recently deployed new HPE Aruba Networking Access Points at different branch offices. Wireless 802.IX authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed. What is the appropriate solution for this scenario?
Options
- AEnable IPSec under Data Handling in HPE Aruba Networking Central
- BConfigure RedSec on the AP and the RADIUS server.
- CEnable EAP-TLS on all wireless devices.
- DEnable EAP-TTLS on all wireless devices.
How the community answered
(34 responses)- A12% (4)
- B79% (27)
- C3% (1)
- D6% (2)
Explanation
RadSec (RADIUS Security, styled "RedSec" in this question) wraps RADIUS traffic in TLS, directly encrypting the authentication messages traveling between the AP and the cloud RADIUS server - this precisely addresses the security team's concern about exposed RADIUS traffic in transit.
Why the distractors are wrong:
- A (IPSec in Aruba Central): IPSec Data Handling in Aruba Central protects GRE tunnel/data-plane traffic, not RADIUS authentication traffic specifically.
- C (EAP-TLS): EAP-TLS secures the authentication exchange between the wireless client and the RADIUS server, but does nothing to encrypt the RADIUS protocol traffic between the AP and the RADIUS server.
- D (EAP-TTLS): Same problem as EAP-TLS - it's a client-side authentication method, not a mechanism to protect the AP-to-RADIUS server transport.
Memory tip: Think of it as "layers of the problem." EAP methods secure the client-to-server relationship; RadSec secures the AP-to-RADIUS pipe. When the question asks about protecting AP↔RADIUS traffic, the answer is always RadSec (TLS for RADIUS, standardized in RFC 6614).
Topics
Community Discussion
No community discussion yet for this question.