HPE7-A08 · Question #94
An existing AOS-10 wireless deployment is expanding its zero-trust wireless network to multiple locations. The requirement is to propagate role information to enforce group-based policies for…
The correct answer is B. Configure "use switch fabric for role propagation" under Security -> Client Roles in HPE Aruba. Enabling "use switch fabric for role propagation" in HPE Aruba's Security → Client Roles settings is the correct mechanism because it allows the AOS-10 gateway fabric to share client role assignments network-wide, ensuring group-based policies are consistently enforced across…
Question
An existing AOS-10 wireless deployment is expanding its zero-trust wireless network to multiple locations. The requirement is to propagate role information to enforce group-based policies for wireless client traffic across all locations. To achieve this goal, which must be configured in this infrastructure?
Options
- AConfigure the gateways to mobility type and configure the Roles under System -> Client Roles in
- BConfigure "use switch fabric for role propagation" under Security -> Client Roles in HPE Aruba
- COverlay campus switch fabric with CX switches
- DTunneled SSIDs with gateways
How the community answered
(40 responses)- A20% (8)
- B68% (27)
- C8% (3)
- D5% (2)
Explanation
Enabling "use switch fabric for role propagation" in HPE Aruba's Security → Client Roles settings is the correct mechanism because it allows the AOS-10 gateway fabric to share client role assignments network-wide, ensuring group-based policies are consistently enforced across all locations without re-authenticating clients at each site.
Why the distractors are wrong:
- A is wrong because configuring gateways to "mobility type" addresses client roaming continuity, not role distribution across a multi-site zero-trust deployment, and the menu path (System → Client Roles) is incorrect for this function.
- C is wrong because overlaying CX switches upgrades wired campus infrastructure but has no direct effect on propagating wireless client roles across locations.
- D is wrong because tunneled SSIDs route wireless traffic through gateways (useful for centralized policy enforcement), but tunneling alone does not propagate role identity to other sites.
Memory tip: Think of the switch fabric as the "nervous system" that carries role identity signals across the whole network - if you want roles to travel everywhere, you tell the fabric to carry them. The setting lives under Security (where policies live) → Client Roles (what you're propagating).
Topics
Community Discussion
No community discussion yet for this question.