Your company has branch wireless controllers that send RADIUS requests to a local NPS server named Branch-NPS. Corporate policy requires that all authentication and accounting be processed on a central NPS at headquarters (HQ-NPS). Branch-NPS must only forward requests based on the NAS-IP-Address of the branch controllers and must not perform local authentication. Which two actions should you perform on Branch-NPS?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Remote RADIUS Server Group that contains HQ-NPS., Create a Connection Request Policy that matches the branch controllers and forwards authentication and accounting to the Remote RADIUS Server Group..
Why this is the answer
To achieve the requirement of forwarding RADIUS requests from Branch-NPS to HQ-NPS without local authentication, you must first define HQ-NPS as a target. This is done by creating a Remote RADIUS Server Group on Branch-NPS and adding HQ-NPS to it. Next, a Connection Request Policy (CRP) is needed to specify when and where requests should be forwarded. This CRP should be configured to match the NAS-IP-Address of the branch controllers and then direct these matching requests to the Remote RADIUS Server Group containing HQ-NPS for both authentication and accounting. Creating a Network Policy on Branch-NPS would lead to local authentication, which is explicitly forbidden by the corporate policy. Adding a realm substitution rule is used for modifying usernames, not for controlling the forwarding of RADIUS requests based on source IP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed