HPE7-A07 · Question #46
A customer is planning to add IoT devices that connect wirelessly to the existing 802.1 X SSID. The customer will use HPE Aruba Networking ClearPass to authenticate the IoT devices by MAC address…
The correct answer is C. Remove mac-authentication from the WLAN configuration. The existing configuration for the WLAN ssid-profile has enabled MAC authentication which, while suitable for IoT devices that may not support 802.1X, can interfere with the normal 802.1X authentication process for other devices. By removing the mac-authentication directive…
Question
A customer is planning to add IoT devices that connect wirelessly to the existing 802.1 X SSID. The customer will use HPE Aruba Networking ClearPass to authenticate the IoT devices by MAC address but other devices will still need to authenticate by only 802.1X. Refer to the exhibit. The customer provided the current configuration and reported their non-IoT 802.1X devices are no longer able to connect. Which configuration change can be made to fix the issue?
Exhibit
Options
- AModify opmode wpa3-aes-gcm-256 to opmode wpa2-aes
- BAdd l2-auth-failthrough to the WLAN configuration
- CRemove mac-authentication from the WLAN configuration
- DModify max-authentication failures to 0
How the community answered
(48 responses)- A13% (6)
- B2% (1)
- C79% (38)
- D6% (3)
Explanation
The existing configuration for the WLAN ssid-profile has enabled MAC authentication which, while suitable for IoT devices that may not support 802.1X, can interfere with the normal 802.1X authentication process for other devices. By removing the mac-authentication directive from the WLAN configuration, the non-IoT 802.1X devices should be able to connect without issues as the authentication process will not be disrupted by MAC authentication checks. This adjustment ensures that the WLAN ssid-profile is correctly aligned with the authentication requirements for both IoT and non-IoT devices within the network environment, conforming to the best practices for mixed-device WLAN configurations.
Topics
Community Discussion
No community discussion yet for this question.
