A.C.P SW
|
|
Title of test:
![]() A.C.P SW Description: AC Pro SW |



| New Comment |
|---|
NO RECORDS |
|
Your customer’s CISO would like to deploy colorless ports across the network. Which will you need to configure to meet this requirement?. Active gateway. Downloadable User Roles. Virtual active forwarding. Downloadable fingerprints. You need to configure BGP on an HPE Aruba Networking switch using AS 65010. What is required when establishing peering with neighboring devices using eBGP that are not directly connected?. Use of next-hop-self. Use of ebgp-multihop. Use of route-reflector. Use of address-family ipv4 external. How would the route type affect the configuration if an OSPF configuration has several external routers?. If you have a primary exit with a secondary backup, you must choose E1, the primary with a lower default metric than the secondary. If you want to consider internal and external costs equally, use E2 routes. If you want to leverage all paths to destinations, use E2 with the same default metric. If you want to use the closest exit point, use E2 with appropriate seed metric. You want to set up NAE to monitor BGP neighbor state changes and create a helpdesk ticket whenever they occur. Which NAE action can you configure to accomplish this?. Execute shell command. Send email. Generate system log. REST API call. The neighbor switch is configured with the following IP interfaces: - mgmt: 172.30.32.8 - loopback 0: 10.255.255.2 - vlan 5: 192.168.5.2 How can you change the advertised management IP information to appear as the VLAN 5 IP?. Under interface vlan 5, issue command: lldp management-address. Issue in global context command: lldp management-address vlan 5. Under lldp context: lldp management-address 192.168.5.2. Issue in global context command: lldp management-ipv4-address vlan 5. Which statement is valid when enabling ARP protection features on an HPE Aruba Networking CX switch?. DHCP server utilization is required for IP to Mac binding to enable ARP protection. Client lease time on the DHCP server should be at least 3600s before enabling ARP protection. Once you enable DHCP snooping, you can enable ARP protection, and you will have full information to mitigate security risks. Configuring IP to MAC address bindings allows ARP protection for networks without a DHCP server. With the given output from an HPE Aruba Networking CX 6300: Which statement about the output above is true?. The accepted AS paths are defined in the aspath-list. The defined route-map is used in BGP with neighbor remote-as export. The advertised AS paths are configured in an IP prefix-list. The route-map with aspath-list intended for iBGP peers. You are reviewing the configuration of a VSX lag and have noticed the command lacp fallback. Why might this have been configured?. To allow operation with active or passive LACP. To support devices that require PXE Boot. For backwards compatibility with LACP v1. For operation using a single partner LACP interface. The primary VSX switch has a DHCP relay configured; however, the secondary switch does not display the DHCP relay configuration in the running configuration. How can the VSX configuration be changed to have the same config on both nodes?. On the secondary switch, add vsx-sync ip-helper under VSX configuration. On the primary switch, add vsx-sync ip-helper under VSX configuration. On the primary switch, add vsx-sync dhcp-relay under VSX configuration. On the secondary switch, add vsx-sync dhcp-relay under VSX configuration. Refer to the partial exhibit from HPE Aruba Networking CX 8325: If a new CX 8325 is to be deployed, which switch profile should be used to provide gateway and routing services?. L3-core profile should be selected instead of the factory default. Spine profile should be used, which is the factory default. Leaf profile should be selected instead of the factory default. The L3-agg profile should be selected instead of using the factory default. According to the HPE Aruba Networking VSX best practices, what would need to be changed in the configuration?. Replace the CX8325 1/1/47 and 1/1/48 ports with SFP28 connectivity. Replace the CX8325 1/1/47 and 1/1/48 ports with SFP56 connectivity. Replace the CX6300[1-2]/1/49 and [1-2]/1/50 ports with QSFP28 connectivity. Replace the CX6300 [1-2]/1/49 and [1-2]/1/50 ports with SPF56 connectivity. You would like to receive a monthly report tracking your available HPE Aruba Networking Central licenses and their expiration dates. Which report should you schedule?. Switch Capacity Planning. Resource Utilization. Network. Infra Inventory. Refer to the exhibit for an HPE Aruba Networking CX 6300M VSF: If Member ID 1 fails, what would be the state of Member ID 2?. Conductor. Standby. Not present. Member. You are helping another engineer troubleshoot a new downloadable user role configuration between your CX switches and ClearPass. Which configuration on the switch should you verify?. SNMP community string. User-role configuration. HTTPS client certificate. Trust Anchor profile. You have attempted to configure DHCP snooping, but it is not working as expected. Based on the output below, what do you need to configure?. Configure an authorized DHCP server. Configure a DHCP trusted interface. Enable dhcpv4-snooping on VLAN 100. Enable dhcpv4-snooping globally. Which HPE Aruba Networking ClearPass configuration is required to implement DUR?. Enable the RadSec service. Create an admin user role. Import RADIUS dictionary attributes. Configure an HTTPS certificate. Match the terminology related to 802.1x authentication. Authenticator. Radius. Authentication server. Supplicant. Your customer's CX switches are managed in HPE Aruba Networking Central. If a VSX primary switch is accidentally powered off, which alert will be triggered?. Switch Reboot. Switch Stack Conductor Change. Switch Disconnected. Switch STP Root Change. Which two configuration tasks must be performed when creating a device profile for an AP? (Select two.). Associate a role. Associate a QoS policy. Associate an LLDP group. Associate a VLAN. Associate an ACL. You are implementing a design where the campus network should be in an isolated spanning tree topology from the data center network. The core switches are connected by a single layer-2 interface carrying multiple VLANs. When you examine the switches you discover that the campus core sees the data center core as the root bridge. Which configuration can you apply to the campus to data center core link to resolve the issue?. Root guard. BPDU filter. BPDU guard. Admin edge. A customer wants to prevent ' man-in-the-middle ' attacks based on Layer 2 addressing. What will help address that concern?. Enable ARP inspection in the VLAN interface context. Enable ARP inspection in the VLAN context. Enable ARP inspection in the global context. Enable ARP inspection in interface-level context. Interfaces 1/1/53 and 1/1/54 were accidentally disconnected from Switch-A, the primary VSX member. Client A is experiencing network disruptions with network connections to Router-A. What needs to be done to prevent user traffic disruption in this scenario?. Configure keepalive VLAN on downstream lag. Configure VSX shutdown on-split on SW-B. Configure keepalive VLAN on upstream lag. Configure VSX shutdown on-split on SW-A. You need to run a packet capture on a CX switch and be able to view the full output on a remote device in real-time. What is the best way to do this?. Configure a mirror session using ERSPAN to a computer running Wireshark. Inspect the summary of the packets in real time on the switch using tcpdump. Configure a mirror session with another port on the switch as the destination. Configure a mirror session to the CPU, use tshark to capture it to a PCAP file. Based on the output, which Local Priority (LP) value will be applied to an incoming packet from interface 2/1/39 marked with DSCP 46 and CoS 7?. Local Priority 1. Local Priority 5. Local Priority 7. Local Priority 0. What should you configure for an interface connected to a device you cannot trust to assign DSCP markings? (Select two.). Configure "qos trust cos". Apply a classifier-based policy to the interface to assign a Local Priority value. Apply a dscp-map to the interface to assign a Local Priority value. Configure Weighted Fair Queuing. Configure "qos trust none". Two companies have merged, and BGP is used for routing. The customer has informed you that they currently have about 3600 routes in the routing table and would like to keep the total number of routes below 5000 A BGP routing table from the company to be merged is provided as an example below: Set the route metrics equal for each prefix. Advertise routes only using a primary path. Enforce routing policies with aggregation. Import only 0.0.0.0/0 route. Refer to the exhibit from an HPE Aruba Networking CX6000: Two CX 6000 switches are configured with the same configuration for LAG 1. What needs to be done to remove the LACP block state?. On one of the switches, change the LACP mode to passive. Change the LACP mode from passive to active on one of the switches. On both of the switches, change the LACP timeout to short. Change the LACP mode from passive to static on one of the switches. Your customer's CX switches are managed in HPE Aruba Networking Central. After enabling monitoring using NAE, you consider upgrading some of your 6200 switches with more powerful 6300 switches. Which report can you run to determine which sites would benefit most from an upgrade?. Infra Inventory. Resource Utilization. Network. Switch Capacity Planning. You are troubleshooting a performance issue with a VSX LAG and have run the following troubleshooting commands: | show run int 1/1/11 | show run int 1/1/11 vsx-peer Which troubleshooting methodology does this exemplify?. Follow the path. Top-down/Bottom-up. Replace configuration. Spot the difference. How does an HPE Aruba Networking CX VSX solution make the hardware replacement of a single switch a non-disruptive operation for Layer 2 configurations?. By the utilization of any of the four reserved ranges as system-MAC addresses. By the VSX-sync option for synchronization of the system-MAC. By entering the primary switch system-MAC on the secondary switch. By allowing the system MAC in the ServiceOS to be changed to the original system MAC. The interface is configured on an HPE Aruba Networking CX 8320 for a VMware server NIC. The server admin complains that the VMware vMotion traffic on VLAN 3903 fails, but the server can ping other peers with a large payload size. What must be done to correct the issue based on the provided interface status and configuration?. The VLAN 3903 is configured with mtu 9198. The interface 1/1/35 is configured with mtu 9198. The VLAN 3903 is configured with jumbo. That interface 1/1/35 is configured with jumbo. You are remotely connected to an HPE Aruba Networking CX 6200F switch using SSH to change the Control Plane ACL, allowing only defined subnets to access the switch. Which AOS CX command allows you to roll back your change if the ACL change is wrongly formed and you can no longer log in to the switch?. Use the checkpoint commit command after you commit the change. Use the checkpoint auto command before you commit the change. Use the checkpoint auto command after you commit the change. Use the checkpoint commit command before you commit the change. How would you explain to a new HPE Aruba Networking CX customer how the switch can protect against use cases of malicious DHCP servers and ARP poisoning in the network where client-to-server communication is required?. The control-plane policy can be configured with the allowed DHCP servers. The system configuration database protects the information of authenticated clients. DHCP-snooping-table and ARP protection will together maintain valid information. Private VLANs can be used to isolate the server resources to protect against false DHCP servers. You are implementing a design where the campus network should be in an isolated spanning tree topology from the data centre network. The core switches are connected by a single Layer-2 interface carrying multiple VLANs. When you examine the switches, you discover that the campus core sees the data centre core as the root bridge. What configuration can you apply to the campus-to-data centre core link to resolve the issue?. Root guard. BPDU filter. Admin edge. BPDU guard. Which statement is valid when enabling ARP protection features on HPE Aruba Networking CX switches?. Once you enable DHCP snooping, you can enable ARP protection, and you will have full information to mitigate security risks. In an active network, you should generally wait at least a week after enabling DHCP snooping to enable ARP protection. Client lease time on the DHCP server should be at least 3600s before enabling ARP protection. DHCP server utilization is required for IP to MAC binding to enable ARP protection. When configuring a multicast solution on HPE Aruba Networking CX switches, what needs to be configured on the core switch to enable L3 multicast routing locally?. IGMP on SVI. IGMP on VLAN. IGMP-snooping on VLAN. IGMP-snooping on SVI. Based on the given output from an HPE Aruba Networking CX6300: Which statement about the output above is true?. The defined route map is used in BGP with neighbor remote-as export. The advertised AS path is longer than by default. The advertised routes have a MED value of 100. The advertised AS paths are configured in an IP prefix-list. You are attempting to configure an interface, but you are seeing the error message below. What could explain this? Access-1(config)# interface 1/1/1 Invalid input: interface. The switch is in password recovery mode. The command must be run from the manager context. The switch is being managed by HPE Aruba Networking Central. Authorization is enabled for CLI commands. You are configuring OSPF between two CX switches but cannot see any neighbors. Based on the output, how would you fix the problem?. Remove the max-metric router-lsa on-startup to allow faster formation of adjacency. Configure ip ospf network broadcast on the VLAN 182 interface. Configure no ip ospf cost 100 on the VLAN 182 interface. Configure no passive-interface vlan182 on the switch. An HPE Aruba Networking Central switch is managed in HPE Aruba Networking Central. If you need to validate configuration changes in the switch’s Global view, what information can you get using the Audit trail?. The configuration changes history is up to 7 years. The configuration difference that was pushed to the device. The method used to create the configuration (template, multi-edit, or GUI). The username of the person who pushed the configuration. After configuring IGMP snooping on a Layer 2 VLAN, multicast applications are no longer working. Which additional configuration step is required?. Enable IGMP snooping on the Layer 3 interface for the VLAN. Enable IGMP on the Layer 3 interface for the VLAN. Enable PIM-SM on the Layer 3 interface for the VLAN. Enable PIM-DM on the Layer 3 interface for the VLAN. You’ve rebooted sw-agg2 in a VSX configuration, after which you see this condition (refer to the exhibit): What can you identify based on this output?. The VSX cluster still syncs configuration changes that are common to both software versions. The VSX cluster is in incompatible mode due to software differences. The VSX cluster can be live upgraded by rebooting sw-agg1. The VSX cluster forwards all traffic through ISL to the primary switch. An HPE Aruba Networking CX switch is configured with IGMP using the given output: Which statement is true about the possible supported message types?. Leave and Report. Join, Leave, Query and Report. Query and Report. Join and Query. According to the HPE Aruba Networking VSX best practices, what would need to be changed on the configuration?. Replace the CX 8325 1/1/47 and 1/1/48 ports with SFP28 connectivity. Replace the CX 8325 1/1/47 and 1/1/48 ports with SFP56 connectivity. Replace the CX 6300 [1-2]/1/49 and [1-2] /1/50 ports with QSFP28 connectivity. Replace the CX 6300 [1-2]/1/49 and [1-2] /1/50 ports with SFP56 connectivity. You have recommended that a customer adopt a modern management approach for their new CX switches. Which of these would this include? (Choose two.). REST API. YAML. SNMP. NAE. XML. A customer has asked if their new CX switches will support their legacy management system. Which of these would this include? (Choose two.). CLI. REST API. NAE. HTTPS. SNMP. OSPF peering is configured between HPE Aruba Networking CX 6300 switches utilizing BFD. You've made this configuration on switch B, while switch A is in the default configuration: Which BFD Tx/Rx interval values will switch A use for the show bfd session?. Switch A show BFD sessions using 500ms. Switch A show BFD sessions using 6000ms. Switch A show BFD sessions using 2000ms. Switch A show BFD sessions using 300ms. You recently enabled ARP protection on your CX switches, but many users now complain that they can no longer access the network. What do you need to configure to resolve the issue?. Dynamic IP lockdown. IGMP snooping. DHCP snooping. DHCP reservations. You are helping another engineer troubleshoot a new downloadable user role configuration between your CX switches and ClearPass. Which configuration on the switch should you verify?. HTTPS client certificate. REST API credentials. SNMP community string. User-role configuration. A multicast configuration on an HPE Aruba Networking CX 6300 VSF is used for a group address 239.0.0.1. The configuration is having issues, and the video streaming clients are not receiving the stream. What would be a possible root cause for the problems experienced?. The IGMP-snooping is using version 2 configured for the SVI. The selected multicast address will overlay with Link-Local Multicast address scope. The selected multicast address will overlay with PIM-SM discovery address. The IGMP is enabled on the VLANs without any multicast traffic. TAC has made a configuration change on the CLI of a CX switch using aruba-central support-mode. Which statement about the switch configuration in HPE Aruba Networking Central is true?. The user must make the same change in HPE Aruba Networking Central for synchronization to occur. HPE Aruba Networking Central will automatically overwrite the configuration change. The configuration change will be automatically synchronized to HPE Aruba Networking Central. Config auto-commit will be disabled and must be re-enabled manually. Which statement about redistributing BGP routes to OSPF is true?. Only the default route should be redistributed to OSPF. Always redistribute BGP routes to OSPF as E1 routes. Always redistribute BGP routes to OSPF as E2 routes. Only defined routes should be redistributed to OSPF. Match each REST API method to the correct description. PATCH:. POST:. GET:. DELETE:. PUT:. When combining Strict Priority (SP) with other queuing types, how can you avoid starvation of lower priority queues?. Apply multiple queuing profiles to the same interface. Configure WFQ DWRR instead of queuing. Apply shaping to queue 7. Configure a higher weight for lower priority queues. Your network monitoring system has issued a critical alert indicating that the ISL between two VSX core switches is down. What can you determine from the log output below?. Core-2 has disabled its VSX LAG interfaces. Keepalive packets are being dropped. Both switches are forwarding traffic over VSX LAGs. Downstream switches are not able to forward traffic. How can you implement route summarization for the routes originating from Area 2?. router ospf 1 area 0 range 10.1.0.0/16 type inter-area. router ospf 1 area 2 range 10.1.0.0/16 summary-only. router ospf 1 area 2 range 10.1.0.0/16 type inter-area. router ospf 1 area 0 range 10.1.0.0/16 summary-only. Your customer is concerned about users connecting unmanaged switches to the network and causing outages. Which CX switch feature should you recommend?. Port security. BPDU Guard. Loop protection. MAC authentication. Company A has an existing HPE Aruba Networking CX 8325 VSX. It has acquired Company B and must merge its networks onto the same VSX switch configuration as Company A. Both Company A and Company B share the same 10.100.100.1/21 subnet. What is the correct order for creating a configuration allowing overlapping networks in the setup?. 1. 2. 3. 4. Which data format do CX switches support for the REST API?. XML. YAML. JSON. SOAP. Which parameters can be configured in a Local User Role? (Choose two.). VLAN. ClearPass server. Description. Authentication method. ACL. Match where the configuration for loop-protection is defined on an AOS-CX switch. Options may be used more than once. Global configuration. Interface configuration. You are implementing a directly connected routing plan using OSPF on an HPE Aruba Networking CX 6200 and ISP router. What would be the impact of changing the network type to point-to-point?. It will reduce the number of LSA type-2 advertisements. A larger number of OSPF routes would be supported. It will increase the number of LSA type-3 advertisements. The configuration would remain as the default. Your company needs to run BGP in a multi-homed configuration to two ISPs, advertising a block of public address space you own. Which AS number would be an example of a suitable number?. 64813. 63472. 65535. 65218. What does it mean when an event such as the one below occurs on the HPE Aruba Networking CX switch? 2024-04-04T08:35:36.312254+00:00 ICX-Core-1 hpe-vsxd[2167]: Event|7012|LOG_INFO|AMM|1/1|VSX 2 state local down, remote up. VSX secondary switch is down. The multichassis LAG 2 interface is down on both switches. The physical interface of LAG 2 on the local VSX member is down. VSX keepalive has detected that the primary member is down. A customer would like to use HPE Aruba Networking Central to monitor and configure switch backups, but does not want to be able to make configuration changes. What can you tell them?. This can be done with the ‘read-only’ device attribute. This is possible for AOS-S switches but not AOS-CX switches. This is possible for AOS-CX switches but not AOS-S switches. This can be done with the ‘Monitoring only’ group option. A database administrator has reported intermittent connectivity issues with a SQL server hosted in the data center and has provided you with the source and destination IP addresses. Which troubleshooting methodology would be the most suitable to start with?. Spot the difference. Follow the path. Divide and conquer. Top-down/Bottom-up. You are deploying a pair of VSX switches parallel to some existing HPE Comware switches. You would like to configure a common first-hop redundancy protocol as part of your migration strategy. Which of these would be suitable?. Active Forwarding. HSRP. VRRP. Active Gateway. A senior network architect has created the configuration above. You are implementing the setup in Building A and C. The actual fiber distance between the building locations is 200m / 656ft utilizing OM4 cabling. What needs to be changed in the configuration based on the actual environmental conditions to complete the installation and 7 other CX 6300 VSF stack connections in the future?. Replace the 25GR optics with 10SR. Replace the 25GR optics with 25LR. Replace the 25GR optics with 10LR. Replace the 25GR optics with 25SR. You have configured 802.1X and MAC authentication in an office environment. During testing, you noticed that devices that don’t support 802.1X take a few minutes to receive an IP address. What can you do to improve the connection time for these devices while maintaining a secure configuration?. Disable 802.1X on ports connecting to devices that don’t support it. Increase the 802.1X EAPOL timeout value on all ports. Configure auth-precedence to MAC, then 802.1X authentication. Decrease the MAC auth start value on all ports. A customer has connected a server to VLAN 100 on a 6300 switch which is streaming video using multicast group 224.0.0.100. This stream would need to be received by the clients in VLANs 200 and 300, routed on the same CX switch. What needs to be done to enable the requirement?. The multicast group address needs to be changed to a routable subnet. The multicast group address needs to be changed to other 224.0.0.x non-overlapping address. The igmp-snooping needs to be enabled on SVIs 100, 200, and 300. The igmp needs to be enabled on the SVIs 100, 200, and 300. From which sources can you download NAE agent scripts directly from the CX switch UI?. HPE Networking Support Portal. Aruba Solutions Exchange. Airheads Community. GitHub Community. You have applied the following OSPF configuration but are seeing the output from the command below. What is the reason for this?. A loopback interface hasn't been configured on Agg-2. OSPF interfaces are passive by default. A different OSPF process ID is used on each switch. A Layer-3 interface has not been associated with a VRF. You need to find which change was made to the HPE Aruba Networking CX switch from the GUI. Which option can you use?. Use checkpoint diff to compare running-config with stored saved-config revisions. Use show checkpoint diff to compare running-config with stored checkpoints. Use show checkpoint diff to compare running-config with stored saved-config revisions. Use checkpoint diff to compare running-config with stored checkpoints. You are about to make a change to the HPE Aruba Networking CX switch in HPE Aruba Networking Central and are encountering the condition displayed above. What needs to be done to make a change to the switch with multi-edit?. Select configuration status and enable edit config. Enable edit config mode using the gear icon. Override state. Select the device in multi-edit and enable edit config mode. Your customer is a large hotel that would like to use a single VLAN per floor and isolate each room's wired network port from the others. Which CX switch feature should you recommend for the simplest solution?. VPN. UBT. PVLAN. VXLAN. An Aruba CX6100 VSX has the following state for LACP: 2024-06-08T19:48:34.713434+03:00 VSX1 lacpd[837]: Event|1321|LOG_INFO|AMM|1/1|LAG 253 State change for interface 1/1/25:3: Actor state: ALFNCD, Partner state: ASFNCD 2024-06-06T19:48:34.675496+03:00 VSX1 lacpd[837]: Event|1308|LOG_INFO|AMM|1/1|LACP rate set to slow for LAG 253 What can be observed based on the output?. The LAG 253 has a mismatching configuration with a peer. The global LACP rate has been configured for LACP ports. The LAG 253 has been negotiated automatically with peer timeout values. The local LAG 253 has a matching LACP configuration with peer. Your customer’s CISO would like to deploy colorless ports across the network. Which will you need to configure to meet this requirement?. Port-security. MAC Auth. Sticky MAC. Virtual MAC. A recent routing change has caused an outage to one of your customer's branch sites. You are about to run the command below: copy checkpoint 20240722 running-config Which troubleshooting methodology does this exemplify?. Divide and conquer. Top-down/Bottom-up. Replace configuration. Spot the difference. Refer to the exhibit: What is required on the VSF configuration for the stack configuration to work if either member fails?. vsf split-detect mgmt. vsf start-auto-stacking. vsf secondary-member 2. vsf conductor-member 2. You have run a script to configure a new VLAN on a CX switch, but are receiving a '404 - Not Found' HTTP response code. What do you need to do to resolve the issue?. Send a POST request to the /rest/v1/login resource. Correct syntax error contained in the data payload. Enable the switch REST API in read/write mode. Specify the /rest/v1/system/vlan URI in the request. An eBGP configuration is set up from HPE Aruba Networking CX 6300 to two peers. Both peers advertise the 10.200.0.0/23 subnet with the default configuration. What configuration implementation would prefer this route using peer A over B?. Define a route-map with set local-preference 200 and bind it to peer B BGP import configuration. Define a route-map with set metric 200 and bind it to peer A BGP import configuration. Define a route-map with set local-preference 200 and bind it to peer A BGP import configuration. Define a route-map with set metric 200 and bind it to peer B BGP import configuration. You are configuring OSPF on each of the devices shown. After verifying the OSPF neighbor table on each, you notice that Router-1 and Access-1 have neighbors in the 2WAY state. What is the reason for this?. Router-1 and Access-1 have reached a tie in the DR election. Router-1 and Access-1 have no OSPF networks to advertise. This is normal behavior for OSPF neighbors on a broadcast network. IGMP snooping has been configured on Router-1 and Access-1. You recently made a configuration change on a switch, and shortly afterward, you noticed a spike in CPU utilization in the NAE dashboard. You are concerned that the high CPU could be affecting users. What should you do to restore service as quickly as possible?. Reboot the switch. Revert the change. Disable debug logging. Pause NAE monitoring. Refer to the exhibit for an HPE Aruba Networking CX 6300M VSF: What VSF configuration is required for the stack configuration to work and avoid split-brain?. vsf start-auto-stacking. vsf secondary-member 2. vsf conductor-member 2. vsf split-detect mgmt. You have recently configured WMM to DSCP mapping on your HPE Aruba Networking APs and want to make sure that only the correct traffic is prioritized on the wired network. What should you configure to achieve this? (Choose two.). DSCP trust on the AP user-role. DSCP trust on ports connected to APs. LLDP based on QoS policy. Colorless ports. DSCP trust globally. While troubleshooting a scenario in which the customer has added two new line cards on an HPE Aruba Networking CX 6400 switch, the LEDs on the line card do not show light on the first card. Which troubleshooting methodology should you use to isolate the problem?. Spot the difference by comparing the switch configurations. Divide and conquer by swapping the line cards in their slot. Follow the path and check the connectivity from the access switch to the CX 6400. Replace the configuration using the previous checkpoint on the switch. You need to configure BGP on an HPE Aruba Networking switch using AS 65010. What is required when establishing peering with neighboring devices using eBGP AS 65100?. Use of peer AS 65001. Use of route-reflector. Use of directly connected peer. Use of address-family ipv4 internal. You are implementing HPE Aruba Networking CX switches in a hotel environment. Which feature would allow you to use a single subnet for the wired guests, allowing them to utilize only default gateway services and communicate with each other in a conference room but not elsewhere?. By assigning the guest users in the conference room to an isolated VLAN and the gateway to a primary VLAN. By assigning the guest users in the conference room to a community VLAN and the gateway to a primary VLAN. By assigning the guest users in the conference room to a primary VLAN and the gateway to an isolated VLAN. By assigning the guest users in the conference room to an isolated VLAN and the gateway to a community VLAN. You are reviewing the configuration of a VSX LAG and have noticed the command LACP fallback. Why might this have been configured?. For operation using a single partner LACP interface. For backward compatibility with LACP v1. To support provisioning a gateway without LACP. To allow operation with active or passive LACP. A cabling technician has relocated an access point to your company’s boardroom. Users are now reporting choppy video when making a video call from their devices in the boardroom. Which troubleshooting methodology would be the most suitable to start?. Top-down/Bottom-up. Divide and conquer. Replace configuration. Follow the path. For the aggregation layer, you must configure two new HPE Aruba Networking CX 6200M (VSF) switches. LACP link aggregations to downstream access switches using redundant ports from both switches are required. Which configuration example would create the required lag setup on both switches utilizing HPE Aruba Networking clustering and stacking technologies?. int lag 1 no routing lacp mode active vlan trunk allowed all ! int 1/1/1 lag 1 no shutdown ! int 2/1/1 lag 1 no shutdown. int lag 1 multi-chassis no routing no shutdown lacp mode active vlan trunk allowed all ! int 1/1/1 lag 1 no shutdown. int lag 1 no routing no shutdown lacp mode active vlan trunk allowed all ! int 1/1/1 lag 1 no shutdown. int lag 1 multi-chassis no routing no shutdown lacp mode active vlan trunk allowed all ! int 1/1/1 lag 1 no shutdown ! int 2/1/1 lag 1 no shutdown. The customer would like to utilize Dynamic Segmentation for wired users in Building B. Which statement is true about the scenario?. The CX 6100 switches need to have a GRE tunnel to the HPE Aruba Networking 9200. The CX 6100 switches need to have a static VXLAN tunnel to the HPE Aruba Networking CX 8325. The CX 6100 switches would need to be replaced with CX 6300 models. The CX 6100 switches need to have the CX Advanced license applied to support the requirement. A Linux SFTP server is configured for IP address 192.168.1.100, and the CX 6325 switch has a management IP address 192.168.1.200. How can you back up the saved switch configuration to a remote location?. Use the command copy startup-config scp://user@192.168.1.100/switch_config.cfg vrf default on the switch. Use the command scp admin@192.168.1.200:/running config on the SFTP server. Use the command copy startup-config sftp://user@192.168.1.100/switch_config.cfg vrf mgmt on the switch. Use the command scp admin@192.168.1.200:/startup-config on the SFTP server. Which queuing mechanism should you configure to ensure voice traffic is always forwarded with the highest priority?. Weighted Fair Queuing (WFQ). Virtual output queuing (VOQ). First In First Out (FIFO) queuing. Strict Priority (SP) queuing. After enabling 802.1X authentication on all switch ports connected to AOS10 access points, users joining SSIDs in bridge mode no longer receive an IP address. Users of tunnel mode SSIDs are unaffected. What should be done to resolve the issue?. Enable device auth-mode for the assigned AP role. Increase the client-limit value on all ports to 99. Enable MAC authentication on all switch ports. Configure 802.1X on all client devices. How would you describe the firmware upgrade process for an HPE Aruba Networking VSX cluster?. After the upgrade, the vsx-syned process can resume synchronization even if the switches are in a different firmware version. After the upgrade, the vsx-syned process will continue synchronization, once vsx-upgrade commit is issued. During the upgrade, the vsx-syned process will stop synchronization while the software versions are mismatched. During the upgrade, the vsx-syned process will continue synchronization while the software versions are mismatched. A customer has set global qos trust dscp on an HPE Aruba Networking CX 6300 VSF configuration, which replaced the existing HPE Aruba Networking 5406R VSF. After the change, a video streaming service connected to ports 1/1/20 and 2/1/20, bound to LAG 20, no longer maps to the CoS priority queue mappings used in the old configuration. What configuration change would enable priority trust on DSCP by default and on traffic that requires CoS?. int 1/1/20, 2/1/20 qos trust none ! int lag 20 qos trust cos. qos trust dscp, cos. int 1/1/20, 2/1/20 qos trust cos. int lag 20 qos trust cos. You have added a switch with existing configuration to an existing group in HPE Aruba Networking Central but the configuration is not synchronizing. What could cause this?. The switch is configured in a VSX pair, which HPE Aruba Networking Central does not support. The switch is still pending authorization on the organization settings page. The switch cannot establish a management connection with HPE Aruba Networking Central. Only switches with factory default config can be added to a group with existing config. What does it mean when an event like the one below is seen on the HPE Aruba Networking CX switch? 2024-04-04T08:35:38.312254+00:00 ICX-Core-1 hpe-vaxd[2167]: Event[7011|LOG_INFO|AMM1/1|VSX2 state local up, remote down]. VSX secondary switch is down. VSX keepalive has detected that the secondary member is down. The multichassis LAG 2 interface is down on both switches. The physical interface of LAG 2 on the secondary VSX member is down. A recent routing change has caused an outage to one of your customer’s branch sites. You are about to run the command below: copy checkpoint 20240722 running-config Which troubleshooting methodology does this exemplify?. Replace configuration. Top-down/Bottom-up. Spot the difference. Divide and conquer. What is true when describing HPE Aruba Networking VSX ISL to a new customer?. The ISL traffic is always tagged with EF QoS markings. The traffic over the ISL is encapsulated as a GRE tunnel. The ISL LAG automatically includes all configured VLANs. The ISL LAG must allow all configured VLANs. You are verifying a new VSX deployment and have run the following command. Based on the output, which statement is true?. This device has the highest configured VSX priority. ISL failure would result in a split-brain condition. VSX on both switches is in a healthy state. The ISL has been configured in the mgmt VRF. Your customer’s CISO would like to deploy colorless ports across the network. Which will you need to configure to meet this requirement?. 802.1Q. 802.1X. 802.11X. 802.1AD. A database administrator has reported intermittent connectivity issues with a SQL server hosted in the data center and has provided you with the source and destination IP addresses. Which troubleshooting methodology would be the most suitable to start with?. Follow the path. Divide and conquer. Spot the difference. Top-down/Bottom-up. You have configured BFD for OSPF on a CX switch and have noticed the BFD session stays down but the OSPF neighbor state is up. What could explain this behavior?. The remote switch does not support BFD. BFD is not supported on OSPF broadcast links, so OSPF ignores the config. BFD has not been enabled at the global configuration level. The local switch uses OSPFv3, but the remote switch uses OSPFv2. Your customer’s CX switches are managed in HPE Aruba Networking Central. They have recently connected some new AP-615 access points and want to be notified if the switches have any capacity issues. Which alerts should you enable? (Choose two.). Switch Uplink Port Usage. Switch Link Status Change. Switch Port Tx Rate. Switch PoE Utilization. Switch Port Rx Rate. You must enable HTTPS access to an HPE Aruba Networking CX8100 for an SVI 100 created after default settings. How do you meet this requirement?. Use the command https-server vrf mgmt to allow HTTPS access. The HTTPS server is accessible by default. The HTTPS server is accessible only from mgmt VRF. Use the command https-server vrf default to allow HTTPS access. Your customer's CISO would like to deploy colorless ports across the network. Which will you need to configure to meet this requirement?. VRRP. VNBT. VSF. VRF. What are valid NAE agent actions? (Select two). Run a CLI command. Generate an SNMP trap. Generate a local system log. Start/stop a packet capture. Create a new TAC case. Refer to the partial exhibit from an HPE Aruba Networking CX 8325: A new port 1/1/44 needs to be configured to connect to a 2930F, which has the following configuration Which configuration would be used?. Interface 1/1/44 no shutdown no routing vlan trunk native 10 vlan trunk allowed 1,10,20,24,30,40,50,55,60 exit. Interface 1/1/44 enable no routing vlan trunk native 10 vlan trunk allowed 1,20,24,30,40,50,55,60 exit. Interface 1/1/44 enable vlan trunk native 10 vlan trunk allowed 1,10,20,24,30,40,50,55,60 exit. Interface 1/1/44 no shutdown vlan trunk native 10 vlan trunk allowed 1,20,24,30,40,50,55,60 exit. A junior engineer has configured eBGP between two CX switches (Agg-1 and Agg-2) using the configuration below, and tells you that the neighbors are in the ‘Active’ state. What can you tell them?. When configuring eBGP the AS numbers must match. The eBGP multi-hop feature must be configured. Peering using loopback addresses is not supported. The BGP peers are advertising and learning routes. You have configured UBT on your CX switches, but how HTTPS-enabled websites will not load, which you suspect is due to the packet size. To resolve the issue, what should you configure on each device with tunneled traffic?. Path MTU discovery. Fragment reassembly. Jumbo frames. IP fragmentation. You are reviewing the configuration of an aggregation switch and have noticed that VLAN 1 is configured as the native VLAN on all interfaces connected to access switches. Why might this have been configured?. To support LLDP. To support UBT. To support MSTP. To support ZTP. When configuring a multicast solution on HPE Aruba Networking CX switches, what needs to be configured on the access switch to enable efficient traffic flow?. PIM on VLAN. IGMP-snooping on VLAN. IGMP on VLAN. IGMP-snooping on SVI. In an attempt to clear the switch configuration, you’ve issued the command erase all zeroize. What is the result of this task?. The switch clears all user credentials and retains the running configuration. The switch restores the factory-installed AOS-CX image to the switch. The switch runs a secure erase task, deleting the startup-config, and retains admin credential password. The switch runs a secure erase task, deleting all customer data, and may run up to an hour. You are planning a 1 Gbps link between two CX switches. Which type of SFP port will be required?. SFP28. SFP+. SFP. QSFP+. Match each network requirement to the most appropriate routing protocol. Options may be used more than once. eBGP. iBGP. OSPF. Static Routing. Refer to the exhibit Both switches, Core-1 and Core-2, are configured with default spanning-tree priorities. Both switches appear as primary root bridges. What must be done to have only one spanning tree domain?. Create MST instances 1 and 2 on Core-2. Create matching MST configuration on Core-2. Set the spanning tree priority to 1 on Core-1. Set the spanning tree priority to 1 on Core-2. Your customer’s CX switches are managed in HPE Aruba Networking Central. They have recently deployed new cabling to some desks and want to be notified of any physical cabling issues. Which alerts should you enable? (Choose two.). Switch Port Input Errors. Switch Port Rx Rate. Switch Hardware Failure. Switch Uplink Port Usage. Switch Port Duplex Mode. Your customer’s CX switches are managed in HPE Aruba Networking Central. If a VSX primary switch is accidentally powered off, which alert will be triggered?. Switch Reboot. Switch Disconnected. Switch Stack Conductor Change. Switch STP Root Change. Refer to the exhibit The NTP server is configured on the Primary VSX switch, however, the Secondary switch does not display the NTP configuration in the running configuration. How can the VSX configuration be changed to have the same config on both nodes?. On the primary switch, add vsx-sync ntp under VSX configuration. On the secondary switch, add vsx-sync ntp under VSX configuration. On the secondary switch, add vsx-sync time under VSX configuration. On the primary switch, add vsx-sync time under VSX configuration. Your customer has an existing gateway cluster that they are using to tunnel traffic from APs and would like to configure the same for their CX switches.Which tunneling option should you recommend?. UBT. IPSec. GRE. VNBT. Refer to the exhibit: Using the configuration below, you have configured OSPF at a small branch site, which only requires a single default route to reach the Internet and all other sites. When examining the routing table, you still see other OSPF routes besides the default route. What OSPF area type should you configure?. Totally Not-So-Stubby Area. Stub Area. Totally Stubby Area. Not-So-Stubby Area. You are troubleshooting a complex routing issue after a recent change. Your customer has just called and reported that the issue now impacts all users. What should you do next?. Restore the last-known working configuration. Ask the customer to send logs from each user. Explain to the customer what the issue is. Collect a show tech and log a case with TAC. Based on the images provided , which CLI command was used to produce this output?. Use checkpoint diff to compare running-config with stored checkpoints. Use show checkpoint compare to compare running-config with stored saved-config revisions. Use show checkpoint diff to compare running-config with stored checkpoints. Use checkpoint compare to compare running-config with stored saved-config revisions. Your customer’s CX switches are managed in HPE Aruba Networking Central. You plan to deploy new APs connecting to your existing CX switches. Which report can you run to determine if there are enough available ports and PoE capacity?. Infra Inventory. Switch Capacity Planning. Network. Resource Utilization. Refer to the exhibit: SW-A is the Layer 3 gateway for: - Server-A in VLAN 100, subnet 10.100.100.0/24 - Client-A in VLAN 20, subnet 10.100.20.0/24 - Client-B in VLAN 30, subnet 10.100.30.0/24 What must be done to prevent rogue DHCP servers in VLAN 30 on SW-B?. Enable dhcpv4-snooping trust 10.100.100.10 on VLAN 30. Enable dhcpv4-snooping authorized-server 10.100.100.10 on VLAN 30. Enable snooping globally and on VLAN 30. Enable dhcpv4-snooping globally and on interface VLAN 30. The interface is configured on an HPE Aruba Networking CX8320 for a VMware server NIC, and the server admin reports that VMware vMotion traffic on VLAN 3903 fails, but the server can ping other ports with default settings. What must be done to correct the issue based on the provided interface status and configuration?. Configure jumbo on VLAN 3903. Configure jumbo on interface 1/1/36. Configure MTU 9198 on interface 1/1/36. Configure MTU 9198 on VLAN 3903. You have created a LAG interface to a Gateway on a VSX pair using the following commands: interface lag 10 - description Gateway - no shutdown - no routing - vlan trunk native 1 - vlan trunk allowed all - lacp mode active After checking the state of the link aggregation group (LAG) on the Gateway, you can see that only one of the member links is up. What is causing this?. The ‘multi-chassis’ parameter is missing. The ‘vsx-sync’ parameter is missing. The gateway only supports LACP passive. LACP fallback should be enabled. You have added a switch with existing configuration to an existing group in HPE Aruba Networking Central but the configuration is not synchronizing. What could cause this?. Only switches with factory default config can be added to a group with existing config. HPE Aruba networking Central has not been enabled on the local switch configuration. The switch is configured in a VSX pair, which HPE Aruba Networking Central does not support. The switch is still pending authorization on the organization settings page. Refer to the exhibit: Based on the output, which statement is true?. The switch is currently managed by local CLI overrides. The switch has a configuration pushed that has changed the default settings. The switch is set to auto checkpoint creation for auto-rollback, if configuration push fails. The switch requires a commit configuration, once the change is pushed. You've rebooted s-agg2 in a VSX configuration in an attempt to live-upgrade the cluster, and then you see this condition: What would be the correct way to live-upgrade the VSX cluster?. Always reload the primary switch first with the new image. Use the issu update-software option. Use vsx update-software option. Set the VSX to compatibility mode first, before rebooting the secondary switch. The HPE Aruba Networking CX 8320 VSX configuration is running the current software: How do you upgrade the VSX cluster with the least amount of downtime from a remote server 172.25.101.10 reachable from 172.25.102.11?. vsx update-software scp://172.25.101.10/image vrf mgmt. vsx update-software scp://172.25.101.10/image primary. vsx update-software tftp://172.25.101.10/image vrf mgmt. vsx update-software tftp://172.25.101.10/image primary. Refer to the exhibit: The current startup configuration on the HPE Aruba Networking CX 6300 switch no longer includes a device profile that was created on the previous day. Based on the exhibit, how can you validate if the configuration was removed without changing the current configuration?. Use show checkpoint to see the changes created between the available checkpoints. Use checkpoint diff to check for differences between the startup-config and available checkpoints. Use copy startup-config checkpoint <checkpoint-name> to see the changes created between the available checkpoints. Use checkpoint rollback to see the changes created between the available checkpoints. After configuring BFD for OSPF you are receiving monitoring alerts for high CPU utilization on your switches. Based on the configuration below, how should you resolve the issue? bfd ! router ospf 1 bfd all-interfaces. Enable ICMP active mode. Ensure BFD is enabled on all passive OSPF interfaces. Enable BFD echo mode. Disable ICMP redirects. |




