HPE7-A02 · Question #127
A company has AOS-CX switches and HPE Aruba Networking ClearPass Policy Manager (CPPM). The company wants switches to implement 802.1X authentication to CPPM and download user roles. What is one…
The correct answer is C. Configure RADIUS enforcement profiles that specify the HPE-User-Role VSA. Option C is correct because when AOS-CX switches perform 802.1X authentication via RADIUS, CPPM must return the user role to the switch using a RADIUS attribute - specifically the HPE-User-Role VSA (Vendor-Specific Attribute). RADIUS Enforcement Profiles on CPPM define which…
Question
A company has AOS-CX switches and HPE Aruba Networking ClearPass Policy Manager (CPPM). The company wants switches to implement 802.1X authentication to CPPM and download user roles. What is one task that you must complete on CPPM to support this use case?
Options
- AExport roles on CPPM to a file that uses XML format.
- BCreate an admin account for the switch on CPPM with the HPE Aruba Networking User Role
- CConfigure RADIUS enforcement profiles that specify the HPE-User-Role VSA.
- DUpload the switch TPM certificate as a trusted CA certificate with the Others usage.
How the community answered
(19 responses)- A5% (1)
- B11% (2)
- C84% (16)
Explanation
Option C is correct because when AOS-CX switches perform 802.1X authentication via RADIUS, CPPM must return the user role to the switch using a RADIUS attribute - specifically the HPE-User-Role VSA (Vendor-Specific Attribute). RADIUS Enforcement Profiles on CPPM define which attributes are sent back in the Access-Accept response, so without configuring this profile to include the HPE-User-Role VSA, the switch receives no role information and cannot enforce policy.
Why the distractors are wrong:
- A - Roles are not exported to XML files; CPPM delivers them dynamically at authentication time via RADIUS attributes, not static file transfers.
- B - An admin account grants management access to CPPM itself; the switch authenticates end users, not itself, through the RADIUS protocol and needs no special admin account on CPPM.
- D - TPM certificates relate to device identity/trust for features like CPPM's OnGuard or device profiling; they are not required for 802.1X user role download.
Memory tip: Think of the flow - authenticate → authorize → assign role. The role travels back to the switch inside the RADIUS Access-Accept packet as a VSA. If CPPM's Enforcement Profile doesn't include the HPE-User-Role VSA, the role never makes the trip. "No VSA = no role."
Topics
Community Discussion
No community discussion yet for this question.