Juniper Enterprise Routing and Switching - Professional (JNCIP-ENT) JN0-650 Question # 7 Topic 1 Discussion
JN0-650 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1
You have deployed 802.1X with server fail fallback enabled on an EX Series switch and specified the vlan-name feature for all access ports. The RADIUS server is unavailable.
Which two statements are correct in this scenario? (Choose two )
A.
All clients already authenticated will immediately be disconnected before the re-authentication timer expires.
B.
All clients already authenticated will be unaffected until reauthentication is required.
C.
All new clients will be granted access only if their requested VLAN matches the configuration
D.
All new clients will be placed in the referenced VLAN in the configuration and given access.
When 802.1X server fail fallback is enabled with the vlan-name feature, the switch provides a specific survival mechanism for both existing and new sessions when the RADIUS server becomes unreachable.
Existing Clients (Statement B): Clients that have already successfully authenticated are unaffected by the server ' s unavailability in the short term. They maintain their current network access until their specific re-authentication timer expires. Only then will the switch attempt to contact the server again and trigger the fallback action if the server remains down.
New Clients (Statement D): For any new device attempting to connect while the RADIUS server is down, the switch cannot perform a standard authentication. Under the vlan-name fallback configuration, these new clients are automatically placed into the specified fallback VLAN and granted access based on the local policy defined for that VLAN.
Why others are incorrect: Statement A is incorrect because disconnecting active users would cause unnecessary service disruption. Statement C is incorrect because new clients cannot " request " a VLAN during the 802.1X handshake; the switch assigns it based on the fallback configuration.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit