ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 83 - HPE6-A71 discussion

Report
Export

Refer to the exhibit. An administrator implements an L2 cluster of Aruba Mobility Controllers (MCs) as shown in the exhibit. An external RADUIS AAA server authenticates clients associated with the Active User Anchor Controller (A-UAC), where the NAS IP address sent from Controller B is 10.254.1.2.

By default, what happens to the user's session when it is handed over to the Standby UAC (S-UAC) after a failover?

A.
The user's session remains active and RADIUS messages can still be processed between the S-UAC and AAA server.
Answers
A.
The user's session remains active and RADIUS messages can still be processed between the S-UAC and AAA server.
B.
The user's session remains active, but the AAA server cannot implement RADIUS Change of Authorization (CoA).
Answers
B.
The user's session remains active, but the AAA server cannot implement RADIUS Change of Authorization (CoA).
C.
The user's session is disconnected and has to reconnect, and no record of this process is stored on the AAA server.
Answers
C.
The user's session is disconnected and has to reconnect, and no record of this process is stored on the AAA server.
D.
The user's session is disconnected and has to reconnect, but the S-UAC automatically updates the NAS-IP address on the AAA server to record the event.
Answers
D.
The user's session is disconnected and has to reconnect, but the S-UAC automatically updates the NAS-IP address on the AAA server to record the event.
Suggested answer: B

Explanation:

"The Authorization module authenticates clients on the A-UAC and sets the A-UAC IP address as the NAS-IP. External RADIUS servers set the NAS-IP as the A-UAC IP in the client database (Figure 6-17).

This NAS-IP is used later to change client states or attributes.

However, when the client moves to a new UAC, the authentication server is not updated. This means that transactions initiated by the authorization server will fail.

To resolve this issue, you should configure each cluster member to use the Virtual Router Redundancy Protocol (VRRP), as described below. This enables interaction between the cluster and the authorization server. "

asked 16/09/2024
Vasil Ishmatov
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first