nerdexam
HP

HPE7-A02 · Question #74

A company already uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as the RADIUS server for authenticating wireless clients with 802.1X. Now you are setting up 802.1X on AOS-CX switches to…

The correct answer is D. Service rules. Service Rules are CPPM's gatekeepers - they define which incoming RADIUS requests get matched to and processed by a given service. The copied wireless service has rules that match wireless-specific attributes (e.g., NAS-Port-Type = Wireless-802.11 or SSID-based conditions)…

Implementing Advanced Security Features

Question

A company already uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as the RADIUS server for authenticating wireless clients with 802.1X. Now you are setting up 802.1X on AOS-CX switches to authenticate many of those same clients on wired connections. You decide to copy CPPM's wireless 802.1X service and then edit it with a new name and enforcement policy. What else must you change for authentication to work properly?

Options

  • ARole mapping policy
  • BAuthentication methods
  • CAuthentication source
  • DService rules

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    24% (6)
  • C
    8% (2)
  • D
    56% (14)

Explanation

Service Rules are CPPM's gatekeepers - they define which incoming RADIUS requests get matched to and processed by a given service. The copied wireless service has rules that match wireless-specific attributes (e.g., NAS-Port-Type = Wireless-802.11 or SSID-based conditions). When AOS-CX switches send wired 802.1X requests, those attributes will be different (e.g., NAS-Port-Type = Ethernet), so the new service won't match the incoming wired requests until the rules are updated accordingly.

  • A (Role Mapping Policy) is wrong because the same role mapping logic can apply equally to wired clients; it doesn't affect whether CPPM processes the request at all.
  • B (Authentication Methods) is wrong because the same EAP methods (e.g., PEAP, EAP-TLS) used for wireless 802.1X work identically for wired 802.1X - the clients and their supplicants haven't changed.
  • C (Authentication Source) is wrong because the identity store (Active Directory, LDAP, etc.) is the same regardless of connection medium; user credentials don't change based on wired vs. wireless.

Memory tip: Think of Service Rules as the address label on a mail sorter - if the label still says "wireless," the wired packet gets routed to the wrong bin. You must relabel it so wired requests land in the right service.

Topics

#ClearPass service rules#802.1X#wired authentication#service configuration

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice