Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HP Exam HPE6-A78 Topic 4 Question 78 Discussion

Actual exam question for HP's HPE6-A78 exam
Question #: 78
Topic #: 4
[All HPE6-A78 Questions]

A user attempts to connect to an SSID configured on an AOS-8 mobility architecture with Mobility Controllers (MCs) and APs. The SSID enforces WPA3-Enterprise security and uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as the authentication server. The WLAN has initial role, logon, and 802.1X default role, guest.

A user attempts to connect to the SSID, and CPPM sends an Access-Accept with an Aruba-User-Role VSA of "contractor," which exists on the MC.

What does the MC do?

Show Suggested Answer Hide Answer
Suggested Answer: B

In an AOS-8 mobility architecture, the Mobility Controller (MC) manages user roles and policies for wireless clients connecting to SSIDs. When a user connects to an SSID with WPA3-Enterprise security, the MC uses 802.1X authentication to validate the user against an authentication server, in this case, HPE Aruba Networking ClearPass Policy Manager (CPPM). The SSID is configured with specific roles:

Initial role: Applied before authentication begins (not specified in the question, but typically used for pre-authentication access).

Logon role: Applied during the authentication process to allow access to authentication services (e.g., DNS, DHCP, or RADIUS traffic).

802.1X default role (guest): Applied if 802.1X authentication fails or if no specific role is assigned by the RADIUS server after successful authentication.

In this scenario, the user successfully authenticates, and CPPM sends an Access-Accept message with an Aruba-User-Role Vendor-Specific Attribute (VSA) set to 'contractor.' The 'contractor' role exists on the MC, meaning it is a predefined role in the MC's configuration.

When the MC receives the Aruba-User-Role VSA, it applies the specified role ('contractor') to the user session, overriding the default 802.1X role ('guest'). The MC does not combine the contractor role with other roles like logon or guest; it applies only the role specified by the RADIUS server (CPPM) in the Aruba-User-Role VSA. This is the standard behavior in AOS-8 for role assignment after successful authentication when a VSA specifies a role.

Option A, 'Applies the rules in the logon role, then guest role, and the contractor role,' is incorrect because the MC does not apply multiple roles in sequence. The logon role is used only during authentication, and the guest role (default 802.1X role) is overridden by the contractor role specified in the VSA.

Option C, 'Applies the rules in the contractor role and the logon role,' is incorrect because the logon role is no longer applied once authentication is complete; only the contractor role is applied.

Option D, 'Applies the rules in the contractor role and guest role,' is incorrect because the guest role (default 802.1X role) is not applied when a specific role is assigned via the Aruba-User-Role VSA.

The HPE Aruba Networking AOS-8 8.11 User Guide states:

'When a user authenticates successfully via 802.1X, the Mobility Controller applies the role specified in the Aruba-User-Role VSA returned by the RADIUS server in the Access-Accept message. If the role specified in the VSA exists on the controller, it is applied to the user session, overriding any default 802.1X role configured for the WLAN. The controller does not combine the VSA-specified role with other roles, such as the initial, logon, or default roles.' (Page 305, Role Assignment Section)

Additionally, the HPE Aruba Networking ClearPass Policy Manager 6.11 User Guide notes:

'ClearPass can send the Aruba-User-Role VSA in a RADIUS Access-Accept message to assign a specific role to the user on Aruba Mobility Controllers. The role specified in the VSA takes precedence over any default roles configured on the WLAN, ensuring that the user is placed in the intended role.' (Page 289, RADIUS Enforcement Section)

:

HPE Aruba Networking AOS-8 8.11 User Guide, Role Assignment Section, Page 305.

HPE Aruba Networking ClearPass Policy Manager 6.11 User Guide, RADIUS Enforcement Section, Page 289.

===========


Contribute your Thoughts:

Amber
29 days ago
I believe the MC applies the rules in the contractor role and the logon role.
upvoted 0 times
...
Sylvie
1 months ago
Haha, this is like a game of 'Choose Your Own Adventure' for network admins. I just hope the user doesn't end up in 'The Pit of Despair' when trying to connect!
upvoted 0 times
Aaron
16 days ago
A: C) Applies the rules in the contractor role and the logon role
upvoted 0 times
...
Samuel
23 days ago
B: So the MC will only apply the rules in the contractor role?
upvoted 0 times
...
Hassie
27 days ago
A: B) Applies the rules in the contractor role
upvoted 0 times
...
...
Twila
1 months ago
Hold up, what if the contractor role is more restrictive than the guest role? Wouldn't the MC need to apply both the contractor and guest roles? Option D could be the way to go.
upvoted 0 times
...
Toshia
1 months ago
Hmm, I'm not so sure. What if the contractor role is a subset of the logon role? Wouldn't the MC need to apply both? Option C might be the right answer.
upvoted 0 times
Chana
20 days ago
User 2: That makes sense. The contractor role could be a subset of the logon role, so both sets of rules would need to be applied.
upvoted 0 times
...
Lacresha
21 days ago
User 1: I think option C is correct. The MC would apply the rules in the contractor role and the logon role.
upvoted 0 times
...
...
Jesusa
1 months ago
I agree with Shayne. The contractor role takes precedence over the other roles, so the MC should apply the rules for that role.
upvoted 0 times
...
Nan
2 months ago
I agree with Percy, the MC should only apply the rules in the contractor role.
upvoted 0 times
...
Percy
2 months ago
I think the MC applies the rules in the contractor role.
upvoted 0 times
...
Shayne
2 months ago
The MC should apply the rules in the contractor role, since that's the role specified in the CPPM response. Option B is the correct answer.
upvoted 0 times
Melissa
8 days ago
Paola: That's correct. The MC will apply the rules specified in the contractor role.
upvoted 0 times
...
Venita
14 days ago
User 3: So, the MC will only apply the rules in the contractor role?
upvoted 0 times
...
Paola
22 days ago
User 2: Yes, that's correct. Option B is the right answer.
upvoted 0 times
...
Tonette
1 months ago
User 1: The MC should apply the rules in the contractor role.
upvoted 0 times
...
...

Save Cancel