HPE7-A08 · Question #73
You are remotely connected to an HPE Aruba Networking CX 6200M switch using SSH to change the Control Plane ACL, allowing only defined subnets to access the switch with the assistance of the…
The correct answer is A. Use the checkpoint commit command before you commit the change. When using checkpoint auto, the switch creates a temporary rollback point. If you make a configuration change -- such as modifying the control-plane ACL -- you must commit the checkpoint for the change to become permanent. Without running checkpoint commit, the switch keeps the…
Question
You are remotely connected to an HPE Aruba Networking CX 6200M switch using SSH to change the Control Plane ACL, allowing only defined subnets to access the switch with the assistance of the checkpoint auto 10 command. Later in the day, you are testing if the control- plane ACL is working, and you notice that access is allowed from all networks. What needs to be done with the checkpoint feature to have the remaining without rolling back?
Options
- AUse the checkpoint commit command before you commit the change.
- BUse the checkpoint commit after you commit the change.
- CUse the checkpoint auto command after you commit the change.
- DUse the checkpoint auto command before you commit the change.
How the community answered
(30 responses)- A60% (18)
- B23% (7)
- C10% (3)
- D7% (2)
Explanation
When using checkpoint auto, the switch creates a temporary rollback point. If you make a configuration change -- such as modifying the control-plane ACL -- you must commit the checkpoint for the change to become permanent. Without running checkpoint commit, the switch keeps the configuration in a pending state, and after the auto-rollback timer expires, the switch restores the previous (less restrictive) ACL, which is why all networks are still allowed.
Topics
Community Discussion
No community discussion yet for this question.