HPE7-A07 · Question #30
A customer has deployed an AOS-10 mobility gateway cluster consisting of three controllers at a single site. The WLAN is configured to tunnel wireless device traffic to the AOS-10 mobility cluster…
The correct answer is D. enable Dynamic Authorization CoA under High Availability - Cluster Configuration E. modify NAS IPv4 address under Security - Advanced - RADIUS Client. To ensure that ClearPass can initiate a Change of Authorization (CoA) consistently, it's important to enable dynamic authorization to allow RADIUS CoA messages to be processed. This setting typically falls under the high-availability cluster configuration to ensure that it…
Question
A customer has deployed an AOS-10 mobility gateway cluster consisting of three controllers at a single site. The WLAN is configured to tunnel wireless device traffic to the AOS-10 mobility cluster. The clients are authenticated by HPE Aruba Networking ClearPass using WPA3- Enterprise (opmode wpa3-aes-ccm-128). The security team has requested the ability to force a wireless device to reauthenticate using ClearPass. Which steps are required to ensure ClearPass can consistently initiate a change of authorization against an AOS-10 mobility cluster, including during gateway failover scenarios? (Choose two.)
Options
- Aset cluster mode to Auto Site under High Availability - Cluster configuration
- Bmodify WLAN - SSID - VLAN - Mode Configuration
- Cenable manual cluster configuration under High Availability - Cluster Configuration
- Denable Dynamic Authorization CoA under High Availability - Cluster Configuration
- Emodify NAS IPv4 address under Security - Advanced - RADIUS Client
How the community answered
(30 responses)- A17% (5)
- B10% (3)
- C3% (1)
- D70% (21)
Explanation
To ensure that ClearPass can initiate a Change of Authorization (CoA) consistently, it's important to enable dynamic authorization to allow RADIUS CoA messages to be processed. This setting typically falls under the high-availability cluster configuration to ensure that it persists across gateway failovers. Additionally, the NAS IP address must be configured under RADIUS client settings to ensure that the correct IP address is used for RADIUS communications, which is necessary for CoA to function correctly.
Topics
Community Discussion
No community discussion yet for this question.