JN0-643 · Question #151
Host 1, Host 2, and Host 3 are connected to Switch A on interface ge-0/0/2. Host 1 and Host 2 do not support 802.1X. They can authenticate and connect to the Internet. Host 3 was added and it…
The correct answer is B. Disable MAC RADIUS Restrict option on ge-0/0/2. See the full explanation below for the reasoning.
Question
Host 1, Host 2, and Host 3 are connected to Switch A on interface ge-0/0/2. Host 1 and Host 2 do not support 802.1X. They can authenticate and connect to the Internet. Host 3 was added and it supports 802.1X; however, it is unable to authenticate. user@SwitchA> show dot1x interface detail ge-0/0/2.0 ge-0/0/2.0 RolE. Authenticator Administrative statE. Auto Supplicant modE. Multiple Number of retries: 3 Quiet perioD. 60 seconds Transmit perioD. 30 seconds Mac Radius: Enabled Mac Radius Restrict: Enabled Reauthentication: Enabled Configured Reauthentication interval: 3600 seconds Supplicant timeout: 30 seconds Server timeout: 30 seconds Maximum EAPOL requests: 2 Guest VLAN member: <not configured> Number of connected supplicants: 2 user@SwitchA> Referring to the exhibit, how do you allow Host 3 to authenticate to the network but maintain secure access?
Options
- AEnable fallback authentication for 802.1X.
- BDisable MAC RADIUS Restrict option on ge-0/0/2.
- CDisable MAC RADIUS option on ge-0/0/2.
- DEnable Administrative mode for 802.1X.
How the community answered
(62 responses)- A6% (4)
- B77% (48)
- C13% (8)
- D3% (2)
Community Discussion
No community discussion yet for this question.