Users Guide

Table Of Contents
Dell PowerConnect W-Series ArubaOS 6.1 | User Guide 802.1x Authentication | 297
The examples show how to configure using the WebUI and CLI commands.
Authentication with an 802.1x RADIUS Server
An EAP-compliant RADIUS server provides the 802.1x authentication. The RADIUS server administrator
must configure the server to support this authentication. The administrator must also configure the server to
all communications with the Dell controller.
The authentication type is WPA. From the 802.1x authentication exchange, the client and the controller
derive dynamic keys to encrypt data transmitted on the wireless network.
802.1x authentication based on PEAP with MS-CHAPv2 provides both computer and user authentication. If
a user attempts to log in without the computer being authenticated first, the user is placed into a more
limited “guest” user role.
Windows domain credentials are used for computer authentication, and the user’s Windows login and
password are used for user authentication. A single user sign-on facilitates both authentication to the wireless
network and access to the Windows server resources.
Configuring Roles and Policies
You can create the following policies and user roles for:
Student
Faculty
Guest
Sysadming
Computer
Creating the Student Role and Policy
The student policy prevents students from using telnet, POP3, FTP, SMTP, SNMP, or SSH to the wired portion
of the network. The student policy is mapped to the student user role.
Using the WebUI
1. Navigate to the Configuration > Security > Access Control > Policies page. Select Add to add the student
policy.
2. For Policy Name, enter student.
3. For Policy Type, select IPv4 Session.
4. Under Rules, select Add to add rules for the policy.
a. Under Source, select user.
b. Under Destination, select alias.
c. Under the alias selection, click New. For Destination Name, enter “Internal Network”. Click Add to add a
rule. For Rule Type, select network. For IP Address, enter 10.0.0.0. For Network Mask/Range, enter
255.0.0.0. Click Add to add the network range. Repeat these steps to add the network range 172.16.0.0
255.255.0.0. Click Done. The alias “Internal Network” appears in the Destination menu. This step defines
NOTE: Appendix D, “” on page 787describes how to configure the Microsoft Internet Authentication Server and Windows XP
wireless client to operate with the controller configuration shown in this section.
NOTE: The following step defines an alias representing all internal network addresses. Once defined, you can use the alias for
other rules and policies.