ExamGecko
Question list
Search
Search

Related questions











Question 26 - HPE7-A01 discussion

Report
Export

A network engineer recently identified that a wired device connected to a CX Switch is misbehaving on the network To address this issue, a new ClearPass policy has been put in place to prevent this device from connecting to the network again.

Which steps need to be implemented to allow ClearPass to perform a CoA and change the access for this wired device? (Select two.)

A.
Confirm that NTP is configured on the switch and ClearPass
Answers
A.
Confirm that NTP is configured on the switch and ClearPass
B.
Configure dynamic authorization on the switch.
Answers
B.
Configure dynamic authorization on the switch.
C.
Bounce the switchport
Answers
C.
Bounce the switchport
D.
Use Dynamic Segmentation.
Answers
D.
Use Dynamic Segmentation.
E.
Configure dynamic authorization on the switchport
Answers
E.
Configure dynamic authorization on the switchport
Suggested answer: B, C

Explanation:

CoA (Change of Authorization) is a feature that allows ClearPass to dynamically change the authorization and access privileges of a device after it has been authenticated1.CoA uses RADIUS messages to communicate with the network device and instruct it to perform an action, such as reauthenticating the device, applying a new VLAN or user role, or disconnecting the device2.

To enable CoA on a CX switch, the network engineer needs to configure dynamic authorization on the switch, which is a global command that allows the switch to accept RADIUS messages from ClearPass and execute the requested actions3.The network engineer also needs to specify the IP address and shared secret of ClearPass as a dynamic authorization client on the switch3.

To trigger CoA for a specific wired device, the network engineer needs to bounce the switchport, which is an action that temporarily disables and re-enables the port where the device is connected. This forces the device to reauthenticate and receive the new policy from ClearPass. Bouncing the switchport can be done manually by using the interface shutdown and no shutdown commands, or automatically by using ClearPass as a CoA server and sending a RADIUS message with the Port-Bounce-Host AVP (Attribute-Value Pair).

asked 16/09/2024
Jacquezz Shorter
23 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first