HPE6-A68 Exam QuestionsBrowse all questions from this exam

HPE6-A68 Exam - Question 34


A customer wants to implement Virtual IP redundancy, such that in case of a ClearPass server outage. 802.1x authentications will not be interrupted. The administrator has enabled a single Virtual IP address on two ClearPass servers.

Which statement is true? (Choose two.)

Show Answer
Correct Answer: BE

To implement Virtual IP redundancy in ClearPass, the primary node will handle all authentication requests sent to the Virtual IP address when it is active. This ensures there is no interruption in 802.1x authentications if the primary node remains operational. The NAD (Network Access Device) should be configured with the virtual IP address for RADIUS authentications, utilizing the redundancy feature properly. This configuration allows seamless failover to secondary nodes if the primary node becomes unavailable.

Discussion

4 comments
Sign in to comment
tezkOptions: BE
Oct 24, 2022

from comments under Herman's video (from Jo2241 cooment): "Herman Robers There is no real need. If you want to load-balance between the two devices, it may be good to have two virtual IPs which can mutually fail over. For just redundancy, a single VIP is fine. And you can also still use the radius server backup in your switches, APs, etc, but that in general is slower than a virtual IP on the ClearPass. I found that this works for me, in other situations different approaches may work. Also, if you are at the point where the choice between one or multiple VIPs really makes impact, you probably should have a look at an external network load balancer as that is even faster and much more flexible in how you route/distribute your traffic." BE is correct

FyrithOptions: BE
Mar 22, 2023

If you have two virtual IPs, you can just have no virtual IP, it defeats the whole purpose... I think BE makes the most sense here.

hujinkiOptions: BE
Aug 25, 2022

Virtual IP redundancy is an "active / passive" feature. Only one Clearpass server can answer to requests sent to the virtual IP. The NAD must send his requests to the virtual IP in order to benefit from redundancy. Answers are B and E

Jo2241Options: DE
Oct 20, 2022

We should have 2 VIP for redundancy, see Herman's video around 6:00 https://www.youtube.com/watch?v=yUTZcDwaEvM