nerdexam
HP

HPE7-A06 · Question #105

A customer is trialing the below colorless port configuration on a single switch and has noticed that users roaming to access points connected to the test switch are unable to receive an IP address…

The correct answer is B. port-access role Access_Point. For AP uplinks carrying bridged SSIDs, the switchport must authenticate only the AP and then treat all client MACs as part of the same trusted device. Enabling auth-mode device-mode under the Access_Point port-access role ensures the AP is authenticated (MAC-auth), the trunk is…

Troubleshooting and Optimization of Campus Access Switching

Question

A customer is trialing the below colorless port configuration on a single switch and has noticed that users roaming to access points connected to the test switch are unable to receive an IP address on the corporate Wi-Fi network, which is operating in bridged mode. All other SSIDs are working as expected and the AP is Online in HPE Aruba Networking Central. The security team reports that there have been no failed authentications in HPE Aruba Networking ClearPass Access Tracker and that the last entry for the wired port is returning the REDIUS Aruba-User-Role attribute ‘Access_Point’. Which configuration change is required to resolve the issue?

Exhibit

HPE7-A06 question #105 exhibit

Options

  • Aport-access client-move enable
  • Bport-access role Access_Point
  • Cinterface 1/1/1-1/1/48
  • Dinterface 1/1/1-1/1/48

How the community answered

(71 responses)
  • A
    20% (14)
  • B
    61% (43)
  • C
    7% (5)
  • D
    13% (9)

Explanation

For AP uplinks carrying bridged SSIDs, the switchport must authenticate only the AP and then treat all client MACs as part of the same trusted device. Enabling auth-mode device-mode under the Access_Point port-access role ensures the AP is authenticated (MAC-auth), the trunk is applied, and the switch does not attempt to re-authenticate wireless client MACs - allowing clients on the corporate SSID to obtain IP addresses.

Topics

#colorless port#port-access role#ClearPass#802.1X

Community Discussion

No community discussion yet for this question.

Full HPE7-A06 Practice