exam questions

Exam HPE6-A84 All Questions

View all questions & answers for the HPE6-A84 exam

Exam HPE6-A84 topic 1 question 4 discussion

Actual exam question from HP's HPE6-A84
Question #: 4
Topic #: 1
[All HPE6-A84 Questions]

A company has an Aruba ClearPass server at 10.47.47.8, FQDN radius.acnsxtest.local. This exhibit shows ClearPass Policy Manager's (CPPM's) settings for an Aruba Mobility Controller (MC).

The MC is already configured with RADIUS authentication settings for CPPM, and RADIUS requests between the MC and CPPM are working. A network admin enters and commits this command to enable dynamic authorization on the MC: aaa rfc-3576-server 10.47.47.8
But when CPPM sends CoA requests to the MC, they are not working. This exhibit shows the RFC 3576 server statistics on the MC:

How could you fix this issue?

  • A. Change the UDP port in the MCs’ RFC 3576 server config to 3799.
  • B. Enable RadSec on the MCs’ RFC 3676 server config.
  • C. Configure the MC to obtain the time from a valid NTP server.
  • D. Make sure that CPPM is using an ArubaOS Wireless RADIUS CoA enforcement profile.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
6 months, 2 weeks ago
I think the answer is B. When you define RFC 3576 server you define IP address and shared key. The default value is UDP port 3799. RADSEC (Secure RADIUS) auth port 2083 and it used Certificates. When the TLS tunnel is established, RADIUS packets will go through the tunnel and server adds CoA on this tunnel. By default, the TCP port 2083 is assigned for RadSec. Separate ports are not used for authentication, accounting and dynamic authorization changes.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago