An Aruba controller is configured with the correct IP address and gateway information, and is connected to the corporate LAN through a core Layer 3 switch. Control Plane Security (CPSec) is not enabled on the network. An access point is provisioned with the AP name and group, and connected to a different Layer 2 switch on the corporate LAN that has IP connectivity to the core layer 3 switch. The AP powers on and Layer 2 connects to the network, but the wireless radios do not power on.
What could cause this condition? (Select two)
A. The AP's MAC address needs to be configured in the Aruba controller whitelist.
B. The AP and controller are in different subnets.
C. The Layer 2 switches have ACLs that block IPSec traffic.
D. The Layer 2 switches are configured to block IPSec traffic.
E. A DHCP server is not configured for the segment to which the AP is connected.
The network administrator wishes to terminate the VPN encryption on the Aruba controller. When writing a firewall rule to accomplish the task of automatically moving the VPN traffic for the wireless clients from a third party VPN concentrator to an Aruba controller, which action needs to be configured in the rule?
A. redirect to ESI group
B. source NAT
C. destination NAT
D. redirect to tunnel
A controller is provisioned in L3 Mode for Wireless Users. What must be configured on the controller to enable DHCP requests to an external DHCP server?
A. an IP helper command
B. the IP address of the DNS server
C. the IP address of the APs
D. the subnet address of the DHCP server
E. the DHCP server IPSEC Key
A port firewall policy is applied to a trunk port that denies controller access. An "allow all" VLAN firewall policy is applied to VLAN 33 on the same port. A user connected to VLAN 33 on that port attempts to gain access to the controller. Which of the following statements is true?
A. The Port policy is applied, therefore no controller access
B. The VLAN policy is applied, then the port policy, therefore no controller access
C. The VLAN policy is applied, therefore access to the controller is allowed
D. You cannot place a firewall policy on a Ports VLAN when the Port already has a policy, therefore no controller access
E. When locally connected to a controller's port you always have controller access
Which of the following are NOT valid RAP forwarding modes (Choose two)?
A. Tunnel
B. Bridge
C. Split-Tunnel
D. Backup
E. Standard
When deploying Remote Mesh Portals, what is one of the purposes of the Mesh Private VLAN?
A. To separate wireless user traffic coming from mesh networks from non-mesh networks
B. To tag mesh wireless user traffic on a particular AP
C. To allow Mesh Points to form private vlan networks with certain users
D. To tag control plane traffic from Mesh points to the controller
An AP135 has been configured with 3 SSIDs supported on both 2.4Ghz and 5Ghz bands. How many GRE tunnels will be created between the AP 135 and the controller?
A. 3
B. 4
C. 6
D. 7
E. 8
How does the ARM Band Steering feature encourage 5GHz capable clients to move/connect to the 5GHz radios of Aruba APs?
A. ARM "hides" the 2.4GHz radios from 5GHz capable clients
B. ARM utilizes third party software on the wireless clients
C. Current Wi-Fi chipset firmware supports this by default
D. It's not possible the move clients to 5GHz radios when they can see both 2.4 and 5GHz APs
The reusable Aruba Controller wizards are accessible in what way?
A. Only on startup through the CLI
B. Through the CLI, after the initial CLI wizard has been completed
C. In the Web UI under maintenance.
D. In the Web UI under configuration.
E. Must be initialized from CLI first.
An AP resolved DNS and found the master controller. How will this AP be redirected to a Local controller?
A. Based on the AP-Groups CONTROLLER-IP attribute
B. Based on the AP-Groups LMS-IP attribute
C. In AP-provisioning set the LMS-IP attribute D. Must be statically configured to find the local controller
E. In AP-Provisioning set the CONTROLLER-IP attribute