HPE7-A08 · Question #107
In a WLAN network with a tunneled SSID, you see the following events in HPE Aruba Networking Central: The customer asks you to investigate log messages. What should you tell them?
The correct answer is D. This is normal, expected behavior. No further actions are needed. Option D is correct because in a tunneled SSID deployment (where client traffic is encapsulated and forwarded through a GRE tunnel to a gateway), the log messages visible in Aruba Central are a normal artifact of the tunneling process itself - events like station…
Question
In a WLAN network with a tunneled SSID, you see the following events in HPE Aruba Networking Central:
The customer asks you to investigate log messages. What should you tell them?
Exhibit
Options
- AThis indicates a security issue. The client with a MAC address ending with 37:18:0d is performing
- BThere is a roaming issue. Enable Fast Roaming 802.11r and OKC to resolve the issue
- CThis indicates a client WLAN driver issue for the client with a MAC address ending with 37:18:0d.
- DThis is normal, expected behavior. No further actions are needed
How the community answered
(23 responses)- A4% (1)
- B13% (3)
- C4% (1)
- D78% (18)
Explanation
Option D is correct because in a tunneled SSID deployment (where client traffic is encapsulated and forwarded through a GRE tunnel to a gateway), the log messages visible in Aruba Central are a normal artifact of the tunneling process itself - events like station deletion/re-addition, deauthentication, or re-association are expected as the tunnel is established and maintained.
Option A is wrong because the log events are not indicators of a malicious activity; they are infrastructure-driven events tied to how tunnel mode handles client sessions, not client-initiated attacks. Option B is wrong because the logs do not reflect a roaming failure - 802.11r/OKC addresses fast BSS transitions, which is a separate concern unrelated to tunneled SSID session events. Option C is wrong because the behavior is driven by the AP/gateway interaction in tunnel mode, not by a defect in the specific client's wireless driver.
Memory tip: Associate "Tunneled SSID = traffic engineering overhead" - the tunnel creates extra control-plane chatter (deauths, re-associations, station state changes) that looks alarming but is by design. On the exam, if a question pairs "tunneled SSID" with "unusual log messages," your first instinct should be: is this just the tunnel doing its job?
Topics
Community Discussion
No community discussion yet for this question.
