HPE7-A02 · Question #108
An admin has configured an AOS-CX switch with these settings: port-access role employees vlan access name employees This switch is also configured with CPPM as its RADIUS server. Which enforcement…
The correct answer is D. RADIUS Enforcement type with Aruba-User-Role VSA set to "employees". To ensure that the AOS-CX switch properly assigns the "employees" role when using CPPM (ClearPass Policy Manager) as the RADIUS server, you should configure a RADIUS Enforcement profile on CPPM with the Aruba-User-Role VSA (Vendor-Specific Attribute) set to "employees". This…
Question
An admin has configured an AOS-CX switch with these settings:
port-access role employees vlan access name employees This switch is also configured with CPPM as its RADIUS server. Which enforcement profile should you configure on CPPM to work with this configuration?
Options
- ARADIUS Enforcement type with HPE-User-Role VSA set to "employees"
- BHPE Aruba Networking Downloadable Role Enforcement type with role name set to "employees"
- CHPE Aruba Networking Downloadable Role Enforcement type with gateway role name set to
- DRADIUS Enforcement type with Aruba-User-Role VSA set to "employees"
How the community answered
(28 responses)- A4% (1)
- B11% (3)
- C4% (1)
- D82% (23)
Explanation
To ensure that the AOS-CX switch properly assigns the "employees" role when using CPPM (ClearPass Policy Manager) as the RADIUS server, you should configure a RADIUS Enforcement profile on CPPM with the Aruba-User-Role VSA (Vendor-Specific Attribute) set to "employees". This configuration ensures that when an endpoint authenticates, CPPM sends the appropriate role assignment to the AOS-CX switch, which then applies the corresponding policies and VLAN settings defined for the "employees" role.
Topics
Community Discussion
No community discussion yet for this question.