An administrator manages an Aruba wireless network. ClearPass is used to centralize AAA functions. The administrator wants to implement server role derivation.
Which information will the ClearPass server return in regards to the user role assignment?
A. RADIUS VSA User-Role
B. Aruba VSA Firewall-Role
C. Aruba VSA Aruba-User-Role
D. RADIUS VSA Firewall-Role
On the Aruba Mobility Master (MM), when is an AP configured to act as Mesh Portal or Mesh Point?
A. when the mesh cluster profile is created
B. at the time of the AP's apboot mode CLI
C. when the APs are provisioned
D. when the mesh radio profile is created
An administrator wants to implement 802.1X authentication on Ethernet ports on branch office controllers. What must the administrator do to implement this policy?
A. Define the port an untrusted, and assign an AAA policy to the port.
B. Define the port as trusted, and assign an AAA policy to the port.
C. Define the port as untrusted, and assign an AAA policy to the VLAN.
D. Define the port as trusted, and assign an AAA policy to the VLAN.
An administrator wants to implement the MultiZone feature in a company's network to segregate corporate and guest traffic. Corporate traffic will have APs establish connections to a cluster managed by a Mobility Master (MM), and guest traffic will have the same APs establish connections to a standalone controller at the company's DMZ.
What is true about the implementation of MultiZones in this scenario?
A. The MultiZone feature must be enabled in the data zone.
B. The primary zone maintains full control of AP management and configuration.
C. The primary and data zones must be in the same L2 subnet.
D. A MultiZone AP can initially connect to any zone to obtain its configuration.
Refer to the exhibit.
An administrator implements an L2 cluster of Aruba Mobility Controllers (MCs) as shown in the exhibit. An
external RADIUS AAA server authentication clients associated with the Active User Anchor Controller (A
UAC), where the NAS IP address sent from Controller B is 10.254.1.2.
By default, what happens to the user's session when it is handed over to the Standby UAC (S-UAC) after a failover?
A. The user's session remains active and RADIUS messages can still be processed between the S-UAC and AAA server.
B. The user's session remains active, but the AAA server cannot implement RADIUS Change of Authorization (CoA).
C. The user's session is disconnected and has to reconnect, but the S-UAC automatically updates the NAS-IP address on the AAA server to record the event.
D. The user's session is disconnected and has to reconnect, and no record of this process is stored on the AAA server.
A guest establishes an authenticated wireless session to an Aruba Mobility Controller (MC). The controller uses a ClearPass server for all AAA functions.
Which AAA component disconnects the user when the guest exceeds their allowed duration?
A. RADIUS Change of Authorization
B. Active Directory Session Limits
C. RADIUS Authorization Profile
D. SNMP Disconnect
An administrator wants to determine if an IPSec session is established. In order to tunnel and protect the
GRE data traffic between a RAP and an Aruba Mobility Controller (MC).
Which MC command provides this information?
A. show rap-wml
B. show tunneled-node
C. show crypto ipsec sa
D. show crypto isakmp sa
An administrator implements a ClearPass solution to authenticate Aruba wireless users. The Aruba wireless solution is an ArubaOS 8.x Mobility Master (MM) deployment. ClearPass sends an Aruba VSA role name for an authenticated user. However, the administrator notices that the role assigned to the user is different from the one assigned by the ClearPass server.
Which two items should the administrator verify that might be the cause of this problem? (Choose two.)
A. Enablement of user roles on the controller
B. Spelling of the role on the ClearPass server
C. Server-derived role assignment on the ClearPass server
D. Role existence on the Managed Network
E. Order assignment that the controller uses to select a user role
An administrator deploys Aruba Mobility Controller 7005s to a company's branch offices. The administrator wants to disable the console port to prevent unauthorized access to the controllers.
Which controller command should the administrator use to implement this policy?
A. no console enable
B. no mgmt-user console
C. mgmt-user console-block
D. console disable
Which device can terminate to a cluster of Aruba Mobility Controllers (MCs) that run ArubaOS.8.x?
A. BLE Beacon
B. Mobility Master
C. Mesh Point
D. RAP