exam questions

Exam HPE6-A73 All Questions

View all questions & answers for the HPE6-A73 exam

Exam HPE6-A73 topic 1 question 17 discussion

Actual exam question from HP's HPE6-A73
Question #: 17
Topic #: 1
[All HPE6-A73 Questions]

An administrator is implementing a downloadable user role solution involving AOS-CX switches. The AAA solution and the AOS-CX switches can successfully authenticate users; however, the role information fails to download to the switches. What policy should be added to an intermediate firewall to allow the downloadable role function to succeed?

  • A. Allow TCP 443
  • B. Allow UDP 1811
  • C. Allow UDP 8211
  • D. Allow TCP 22
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Letu
2 months, 3 weeks ago
Selected Answer: C
If any firewall or network infrastructure device with ACLs are in the path, they must allow GRE and PAPI traffic. Enable GRE on IP protocol 47 and PAPI on UDP 8211
upvoted 1 times
...
SeidorBruno
6 months, 3 weeks ago
Selected Answer: A
Page 775 Study Guide: This means that a HTTPS certificate has to be installed on the edge switch. [Aruba Networks]
upvoted 3 times
...
E_Nick
1 year, 3 months ago
Selected Answer: A
HTTPS uses TCP 443, so it is A and not C
upvoted 1 times
...
NetExpert
1 year, 3 months ago
A is correct
upvoted 1 times
...
d_nat
1 year, 4 months ago
Selected Answer: A
Answer A is correct. Student Guide Vol2, page 115: "Roles can be configured locally on the switch using a Local User Role (LUR) or on a ClearPass server, using a downloadable user role (DUR). Roles that are configured locally can be assigned via any RADIUS server, using the Aruba-User-Role VSA. When using DUR, the ClearPass HPE-CPPM-Role VSA is used in combination with HTTPS to transfer the role to the switch."
upvoted 4 times
...
JazzyJ151
1 year, 8 months ago
DUR is a CPPM feature, so assumption is that the AAA is CPPM. AOS switches download their roles from CPPM using HTTPS, you just have to put a CA cert on the switch for the CPPM and reference the FQDN. Definitely A.
upvoted 2 times
...
SniBBz
1 year, 9 months ago
Selected Answer: A
Answer is A
upvoted 1 times
...
jordib4
2 years ago
pg 681 from the Aruba guide - "When using DUR, the ClearPass HPE-CPPM-Role VSA is used in combination with HTTPS to transfer the role to the switch." UDP 8211 (PAPI) is related to dynamic segmentation and the communication to the MC not DUR.
upvoted 2 times
...
sentinel44
2 years ago
Selected Answer: A
HTTPS uses TCP 443, so it is A and not C
upvoted 3 times
...
Mar_a_Lagoon
2 years, 2 months ago
REST API is used for this, so A HTTPS
upvoted 3 times
...
kup
2 years, 4 months ago
C only this port mentioned in study book. v2-169
upvoted 1 times
...
Mrvn
2 years, 6 months ago
C is correct (HTTPS is used between switch and CPPM)
upvoted 1 times
[Removed]
2 years, 6 months ago
And HTTPS uses TCP 443, so it is A and not C
upvoted 4 times
...
...
AM1234
2 years, 6 months ago
The correct Answer is A
upvoted 1 times
...
fasty
2 years, 9 months ago
Correct it is A
upvoted 2 times
...
poris27
2 years, 9 months ago
I think the answer Should be A because something wrong with HTTPS maybe the switch failed to download the certificate or there is firewall block TCP443. If UDP 8211 (PAPI) is related for dynamic segmentation instead of DUR
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago