nerdexam
Juniper

JN0-649 · Question #159

You must provide network connectivity to hosts that fail authentication. In this scenario, what would be used in a network secured with 802.1X to satisfy this requirement?

The correct answer is B. Use the server-reject-vlan command to specify a guest VLAN. For a device configured for 802.1X authentication, specify that when the device receives an Extensible Authentication Protocol Over LAN (EAPoL) Access-Reject message during the authentication process between the device and the RADIUS authentication server, supplicants…

Ethernet Switching Features

Question

You must provide network connectivity to hosts that fail authentication. In this scenario, what would be used in a network secured with 802.1X to satisfy this requirement?

Options

  • AConfigure the native-vlan-id parameter on the port.
  • BUse the server-reject-vlan command to specify a guest VLAN.
  • CConfigure a secondary IP address on the port for unauthenticated hosts.
  • DConfigure the port as a spanning tree edge port.

How the community answered

(26 responses)
  • A
    19% (5)
  • B
    69% (18)
  • C
    8% (2)
  • D
    4% (1)

Explanation

For a device configured for 802.1X authentication, specify that when the device receives an Extensible Authentication Protocol Over LAN (EAPoL) Access-Reject message during the authentication process between the device and the RADIUS authentication server, supplicants attempting to access the LAN are granted access and moved to a specific bridge domain or VLAN. Any bridge domain, VLAN name or VLAN ID sent by a RADIUS server as part of the EAPoL Access-Reject message is ignored.

Topics

#802.1X#guest VLAN#server-reject-vlan#authentication failure

Community Discussion

No community discussion yet for this question.

Full JN0-649 Practice