You have a working MAC authentication solution for IoT devices using HPE Aruba Networking ClearPass and want to dynamically change the role of a device based on DHCP fingerprints.
Your security team updated the relevant ClearPass configuration, which will return the 'IoT' Aruba-User-Role VSA if devices match the appropriate profiling rules. The ClearPass appliance is located behind a firewall.
You have deployed the configuration below.

Which actions must be taken for the solution to work? (Choose two.)
Correct Answer: B,D
Dynamic role changes based on DHCP fingerprints require RADIUS CoA (Change of Authorization). You must:
Enable Dynamic Authorization on the switch globally so it will accept CoA requests.

Permit UDP 3799 from ClearPass to the switches through the firewall because CoA is initiated

by ClearPass toward the NAD.