Users Guide

Table Of Contents
116 | Access Points Dell PowerConnect ArubaOS 5.0 | [User Guide
Because all APs discovered by the controller belong to the AP group called “default”, you assign the virtual AP
profile that contains the SSID profile “Corpnet” to the “default” AP group. For the “Guest” SSID, you configure
a new virtual AP profile that you assign to the AP named “building3-lobby”. Table 25 list the profiles that you
need to modify or create for these examples.
Configuring the WLAN
In this example Corpet WLAN, users are validated against a corporate database on a RADIUS authentication
server before they are allowed access to the network. Once validated, users are placed into a specified VLAN
(VLAN 1 in this example) and assigned the user role “employee” that permits access to the corporate network.
Follow the step below to configure the Corpnet WLAN.
1. Configure a policy for the user role employee and configure the user role employee with the specified policy.
2. Configure RADIUS authentication servers and assign them to the corpnet 802.1x authentication server
group.
3. Configure authentication for the WLAN.
a. Create the corpnet 802.1x authentication profile.
b. Create the AAA profile corpnet and specify the previously-configured employee user role for the 802.1x
authentication default role.
c. Specify the previously-configured corpnet 802.1x authentication server group.
4. For the AP group “default”, create and configure the virtual AP corpnet.
a. Create a new virtual AP profile corpnet.
b. Select the previously-configured corpnet AAA profile for this virtual AP.
c. Create a new SSID profile corpnet to configure “Corpnet” for the SSID name and WPA2 for the
authentication.
Configuring the User Role
In this example, the employee user role allows unrestricted access to network resources and is granted only to
users who have been successfully authenticated with an external RADIUS server. You can configure a more
restrictive user role by specifying allowed or disallowed source and destination, protocol, and service for the
traffic. For more information about configuring user roles, see “User Roles” on page283.
Table 25 Profiles for Example Configuration
AP Group/Name Virtual AP Profile SSID Profile AAA Profile
“default” “corpnet”
z VLAN: 1
z SSID profile: “corpnet”
z AAA profile: “corpnet”
“corpnet”
z SSID: Corpnet
z WPA2
“corpnet”
z 802.1x authentication default role:
“employee”
z 802.1x authentication server group:
“corpnet”
- Radius1
- Radius2
“building3-lobby” “guest”
z VLAN: 2
z Deny Time Range
z SSID profile: “guest”
z AAA profile: “default-open”
“guest”
z SSID: Guest
z Open system
“default-open”
(This is a predefined, read-only AAA profile that
specifies open system authentication)
Note: Dell recommends that you assign a unique name to each virtual AP, SSID, and AAA profile that you modify. In this example,
you use the name “corpnet” to identify each of the profiles.