Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam JN0-649 All Questions

View all questions & answers for the JN0-649 exam

Exam JN0-649 topic 1 question 56 discussion

Actual exam question from Juniper's JN0-649
Question #: 56
Topic #: 1
[All JN0-649 Questions]

You are deploying an 802.1X solution and must determine what would happen if clients are unable to re-authenticate to the RADIUS server.
In this scenario, which configuration would provide access to the network if the supplicant is already authenticated?

  • A. move
  • B. permit
  • C. deny
  • D. sustain
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ARSE_TOP
5 months, 2 weeks ago
D is correct, Sustain. "Server fail fallback allows you to specify one of four actions to be taken toward end devices awaiting authentication when the server is timed out: Permit: authentication, allowing traffic to flow from the end device through the interface as if the end device were successfully authenticated by the RADIUS server. Deny: authentication, preventing traffic from flowing from the end device through the interface. This is the default. Move: the end device to a specified VLAN. (The VLAN must already exist on the router.) Sustain: authenticated end devices that already have LAN access and deny unauthenticated end devices. If the RADIUS servers time out during reauthentication, previously authenticated end devices are reauthenticated and new users are denied LAN access. https://www.juniper.net/documentation/us/en/software/junos/user-access/topics/concept/802-1x-pnac-divert-authentication-understanding-mx-series.html
upvoted 1 times
...
yh511
1 year ago
Selected Answer: D
https://www.juniper.net/documentation/us/en/software/junos/user-access/topics/concept/802-1x-pnac-divert-authentication-understanding-mx-series.html
upvoted 1 times
...
harrypogi
1 year, 2 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
piipo
1 year, 5 months ago
Selected Answer: D
D Sustain
upvoted 1 times
...
sanalainen
1 year, 8 months ago
Selected Answer: B
If the RADIUS authentication servers become unavailable or inaccessible the server fail fallback is triggered. By default, the deny option is configured under server-fail, which force fails the supplicant authentication. However, there are other options that you can configure as actions to be taken for end devices awaiting authentication when the server times out. server-fail (bridge-domain bridge-domain | deny | permit | use-cache | vlan-name vlan-name) - deny—Force the supplicant authentication to fail. No traffic will flow through the interface. - permit—Force the supplicant authentication to succeed. Traffic will flow through the interface as if it were successfully authenticated by the RADIUS server. - use-cache—Force the supplicant authentication to succeed only if it was previously authenticated successfully. This action ensures that already authenticated supplicants are not affected.
upvoted 1 times
...
dragossky
1 year, 10 months ago
Selected Answer: D
Permit authentication, allowing traffic to flow from the end device through the interface as if the end device were successfully authenticated by the RADIUS server. Deny authentication, preventing traffic from flowing from the end device through the interface. This is the default. Move the end device to a specified VLAN. (The VLAN must already exist on the router.) Sustain authenticated end devices that already have LAN access and deny unauthenticated end devices. If the RADIUS servers time out during reauthentication, previously authenticated end devices are reauthenticated and new users are denied LAN access.
upvoted 1 times
...
Wallsee
1 year, 11 months ago
should be D
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...