Users Guide

Table Of Contents
Dell PowerConnect W-Series ArubaOS 6.1 | User Guide Virtual APs | 143
key <key>
enable
aaa server-group corpnet
auth-server Radius1
Configuring Authentication
In this example, you create the 802.1x authentication profile corpnet. The AAA profile configures the
authentication for a WLAN. The AAA profile defines the type of authentication (802.1x in this example), the
authentication server group, and the default user role for authenticated users.
In the WebUI
1. Navigate to the Configuration > Security > Authentication > L2 Authentication page. Select 802.1x
Authentication Profile.
a. In the 802.1x Authentication Profile list on the right window pane, enter corpnet in the entry blank at the
bottom of the list, and click Add.
b. Select the corpnet 802.1x authentication profile you just created.
c. You can configure parameters in the Basic or Advanced tabs. These parameters are described in detail in
Table 55. For this example, you use the default values, so click Apply.
2. Select the AAA Profiles tab.
a. Scroll down to the bottom of the AAA Profiles Summary pane, then click Add. An entry blank appears.
b. Enter corpnet, then click Add.
c. Scroll back up the AAA Profiles Summary pane, and select the corpnet AAA profile you just created.
d. For this example, change the 802.1x Authentication Default Role, select the employee role you previously
configured. You can also configure other the AAA profile parameters (see Table 29).
e. Click Apply.
Table 29 AAA Profile Parameters
Parameter Description
Initial role Click the Initial Role drop-down list and select a role for unauthenticated users.
The default role for unauthenticated users is logon.
MAC Authentication Default Role Click the MAC Authentication Default Role drop-down list and select the role
assigned to the user when the device is MAC authenticated. The default role for
MAC authentication is the guest user role. If derivation rules are present, the role
assigned to the client through these rules take precedence over the default role.
NOTE: This feature requires the PEFNG license.
802.1X Authentication Default Role Click the 802.1X Authentication Default Role drop-down list and select the role
assigned to the client after 802.1x authentication. The default role for 802.1x
authentication is the guest user role. If derivation rules are present, the role
assigned to the client through these rules take precedence over the default role.
NOTE: This feature requires the PEFNG license.
RADIUS Interim Accounting When this option is enabled, the RADIUS accounting feature allows the controller
to send Interim-Update messages with current user statistics to the server at
regular intervals. This option is disabled by default, allowing the controller to
send only start and stop messages to the RADIUS accounting server.
User derivation rules Click the User derivation rules drop-down list and specify a user attribute profile
from which the user role or VLAN is derived.
Wired to Wireless Roaming Enable this feature to keep users authenticated when they roam from the wired
side of the network. This feature is enabled by default.