nerdexam
HP

HPE7-A06 · Question #56

The user's device a failing 802.1X with EAP-TLS authentication. We know that the client-side certificate is valid. What is the likely cause of this issue? (Choose two.)

The correct answer is B. There is a problem with the ACL applied to the switch port. C. There is an EAP-type mismatch. A restrictive ACL on the switch port can block required authentication or EAP traffic, causing An EAP-type mismatch between client and network (for example, if the switch or RADIUS is not configured for EAP-TLS) will also cause authentication to fail, even if the certificate is…

Troubleshooting and Optimization of Campus Access Switching

Question

The user’s device a failing 802.1X with EAP-TLS authentication. We know that the client-side certificate is valid. What is the likely cause of this issue? (Choose two.)

Options

  • AThe user's device is not configured to use the correct gateway.
  • BThere is a problem with the ACL applied to the switch port.
  • CThere is an EAP-type mismatch.
  • DThe user's device is using the wrong MAC address.
  • EThe NAD is not able to communicate with DNS servers.

How the community answered

(29 responses)
  • A
    10% (3)
  • B
    79% (23)
  • D
    3% (1)
  • E
    7% (2)

Explanation

A restrictive ACL on the switch port can block required authentication or EAP traffic, causing An EAP-type mismatch between client and network (for example, if the switch or RADIUS is not configured for EAP-TLS) will also cause authentication to fail, even if the certificate is valid.

Topics

#802.1X#EAP-TLS#authentication failure#ACL

Community Discussion

No community discussion yet for this question.

Full HPE7-A06 Practice