An administrator implements interim accounting for guest users so that ClearPass can track the amount of bandwidth that guests upload and download. Guests that abuse bandwidth consumption should be disconnected from the network. The administrator configures the following on the AOS-CX access switches:
After performing this configuration, the administrator notices that guest users that have exceeded the guest bandwidth limit are not being disconnected. Upon further investigation, Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch.
What is causing this issue?
Correct Answer:A
What is correct regarding the configuration of ACLs on AOS-CX switches?
Correct Answer:C
Examine the commands entered on an AOS-CX switch:
What is true regarding this configuration for traffic received on interface 100?
Correct Answer:C
"interface null: equivalent to the policy drop policing action. Any packets matching the class criteria for that policy entry will be dropped and not routed any further."
https://www.arubanetworks.com/techdocs/AOS-CX/10.05/HTML/5200-7300/index.html#GUID-DC7E5E47-8F
More than one next hop can be assigned with an ACL and they work by priority (based on the sequence number: lower sequence number -> higher priority). So next-hop 2.2.2.2 will be used if 1.1.1.1 is not reachable. If both are unreachable, then the packet will be routed looking at the default routing table, if no specific entry will be found, then the pacjet will be routed to the default next hop defined in the ACL.
An administrator wants to track what configuration changes were made on a switch. What should the administrator implement to see the configuration changes on an AOS-CX switch?
Correct Answer:B
An administrator is implementing a downloadable user role solution involving AOS-CX switches. The AAA solution and the AOS-CX switches can successfully authenticate users; however, the role information fails to download to the switches. What policy should be added to an intermediate firewall to allow the downloadable role function to succeed?
Correct Answer:A
pg 681 from the Aruba guide - "When using DUR, the ClearPass HPE-CPPM-Role VSA is used in combination with HTTPS to transfer the role to the switch." UDP 8211 (PAPI) is related to dynamic segmentation and the communication to the MC not DUR.
What is correct regarding rate limiting and egress queue shaping on AOS-CX switches?
Correct Answer:A
you could apply egress queue shaping to the high priority queues to prevent starvation of low priority queues. Egress queue shaping allows you to apply a maximum bandwidth to a priority queue, as well as a burst size. The port buffers excess traffic up to the burst size and sends the buffered traffic at the max rate, smoothing out bursts while also preventing the high priority queue from exceeding its maximum rate and starving out lower priority queues.