HPE7-A06 · Question #17
You have a working MAC authentication solution for IoT devices using HPE Aruba Networking ClearPass and want to dynamically change the role of a device based on DHCP fingerprints. Your security team…
The correct answer is B. Enable Dynamic Authorization in the global context D. Configure the firewall to allow UDP port 3799 from ClearPass to all switches. Dynamic role changes based on DHCP fingerprints require RADIUS CoA (Change of Authorization). You must: Enable Dynamic Authorization on the switch globally so it will accept CoA requests. Permit UDP 3799 from ClearPass to the switches through the firewall because CoA is…
Question
You have a working MAC authentication solution for IoT devices using HPE Aruba Networking ClearPass and want to dynamically change the role of a device based on DHCP fingerprints. Your security team updated the relevant ClearPass configuration, which will return the ‘IoT’ Aruba-User-Role VSA if devices match the appropriate profiling rules. The ClearPass appliance is located behind a firewall. You have deployed the configuration below. Which actions must be taken for the solution to work? (Choose two.)
Exhibit
Options
- AEnable TLS for the RADIUS server
- BEnable Dynamic Authorization in the global context
- CConfigure the firewall UDP port 3799 from all switches to ClearPass
- DConfigure the firewall to allow UDP port 3799 from ClearPass to all switches
- EConfigure an IP helper address with the ClearPass IP address on the IoT VLAN SVI
How the community answered
(32 responses)- A9% (3)
- B56% (18)
- C22% (7)
- E13% (4)
Explanation
Dynamic role changes based on DHCP fingerprints require RADIUS CoA (Change of Authorization). You must: Enable Dynamic Authorization on the switch globally so it will accept CoA requests. Permit UDP 3799 from ClearPass to the switches through the firewall because CoA is initiated by ClearPass toward the NAD.
Topics
Community Discussion
No community discussion yet for this question.
