Which role should the administrator create the rule to deny this traffic?

A company has an Aruba solution with a guest WLAN named exam_guest. A network administrator creates the guest WLAN with the wizard and does not change any of the default roles. The authentication server does not send particular role assignments for authorized users. The company wants to deny guests access to specific IP ranges after the guest authenticate.
For which role should the administrator create the rule to deny this traffic?
A. guest
B. authorized
C. exam_guest-guest-logon
D. guest-logon

Download Printable PDF. VALID exam to help you PASS.

8 thoughts on “Which role should the administrator create the rule to deny this traffic?

    1. answer C is preauthenticated role? then A will be correct for default post authenticated role

  1. C is correct. If you create any guest WLAN , the default role will be the name of your WLAN appended by guest-login.

    2
    2
  2. I don’t agre: Correct Answer is D

    The guest-logon is a user role assigned to any client who associates to the guestnet SSID. Normally, any client that associates to an SSID will be placed into the logon system role. The guest-logon user role is more restrictive than the logon role.

    The guest-logon user role consists of the following ordered policies:

     captiveportal is a predefined policy that allows captive portal authentication.
     guest-logon-access is a policy that you create with the following rules:
     Allows DHCP exchanges between the user and the DHCP server during business hours while blocking other users from responding to DHCP requests.
     Allows ICMP exchanges between the user and the controller during business hours.
     block-internal-access is a policy that you create that denies user access to the internal networks.

  3. Again WRONG Answer …

    Guest logon is the pre-authen role
    Guest is post-authen role, so modify the Guest role to deny guests access to specific IP ranges

    Correct Answer : A

    33

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.