A company has implemented 802.1X authentication on AOS-CX access switches, where two ClearPass servers are used to implement AAA. Each switch has the two servers defined. A network engineer notices the following command configured on the AOS-CX switches:
radius-server tracking user-name monitor password plaintext aruba123 What is the purpose of this configuration?
- Implement replay protection for AAA messages
- Define the account to implement downloadable user roles
- Speed up the AAA authentication process
- Define the account to implement change of authorization
Answer(s): C
Explanation:
Radius service tracking locates the availability of the RADIUS service configured on the switch. It helps to minimize the waiting period for new clients in the unauth-vid (Guest Vlan) when authentication fails because of service is not available, as well as previously authenticated clients in unauth-vid (Guest Vlan) when re-authentication fails because service is not available during the re- authentication period. Note that this feature is disabled by default.
Reference:
https://techhub.hpe.com/eginfolib/networking/docs/switches/WB/16-02/5200-1650_WB_ASG/content/ch04s04.html
Reveal Solution Next Question