nerdexam
HP

HPE7-A08 · Question #137

An AOS-10 multi-site deployment has sites with AP-only bridged SSIDs and other sites with APs and gateways operating tunneled SSIDs. Client session state sync errors exist between secure lab…

The correct answer is D. The sites with issues are the AP-only deployments because the connection to HPE Aruba. In AOS-10 AP-only deployments with bridged SSIDs, there is no gateway to locally maintain and synchronize client session state - the APs must rely on connectivity to HPE Aruba Central (the cloud platform) to perform this function. Secure lab environments typically have…

Implement and Troubleshoot HPE Aruba Networking CX Switch Solutions

Question

An AOS-10 multi-site deployment has sites with AP-only bridged SSIDs and other sites with APs and gateways operating tunneled SSIDs. Client session state sync errors exist between secure lab environments and public-facing areas at several sites. What is causing the issues?

Options

  • AThe sites with issues are the overlay AP with gateway sites because the connection to HPE
  • BThe DTLS connections are down between APs in the lab and APs in public areas.
  • CThe affected clients are associated with an SSID with 11r and 11k disabled.
  • DThe sites with issues are the AP-only deployments because the connection to HPE Aruba

How the community answered

(59 responses)
  • A
    5% (3)
  • B
    19% (11)
  • C
    10% (6)
  • D
    66% (39)

Explanation

In AOS-10 AP-only deployments with bridged SSIDs, there is no gateway to locally maintain and synchronize client session state - the APs must rely on connectivity to HPE Aruba Central (the cloud platform) to perform this function. Secure lab environments typically have restricted or firewalled outbound internet access, which breaks the APs' connection to Aruba Central and causes session state sync failures with public-facing areas that do have cloud connectivity. This makes D correct: the problem is architectural - AP-only sites simply cannot sync session state without their cloud tether.

Why the distractors are wrong:

  • A is wrong because gateway-based (tunneled SSID) sites handle session state locally at the gateway level and are far less dependent on cloud connectivity for sync.
  • B is wrong because DTLS tunnels run between APs and gateways in tunneled deployments - they're irrelevant to AP-only bridged SSID architectures where no gateway exists.
  • C is wrong because 802.11r/11k are client-side roaming optimization protocols; disabling them degrades handoff speed for clients but has no effect on infrastructure-level session state synchronization.

Memory tip: Think "No gateway = no local state = must call home." AP-only sites are cloud-dependent for session sync, so any site with restricted internet (like a secure lab) will break. If you see "bridged SSID + AP-only + secure/isolated environment," think cloud connectivity failure.

Topics

#AOS-10 multi-site#AP-only deployment#client session sync#bridged SSID

Community Discussion

No community discussion yet for this question.

Full HPE7-A08 Practice