Users Guide

Table Of Contents
262 | 802.1x Authentication Dell PowerConnect ArubaOS 5.0 | User Guide
VLAN Assignment with Machine Authentication Enabled
With machine authentication enabled, the VLAN to which a client is assigned (and from which the client obtains
its IP address) depends upon the success or failure of the machine and user authentications. The VLAN that is
ultimately assigned to a client can also depend upon attributes returned by the authentication server or server
derivation rules configured on the controller (see “About VLAN Assignments” on page60). If machine
authentication is successful, the client is assigned the VLAN configured in the virtual AP profile. However, the
client can be assigned a derived VLAN upon successful user authentication.
Table 54 describes VLAN assignment based on the results of the machine and user authentications when VLAN
derivation is used.
Example Configurations
The following examples show basic configurations on the controller for:
z “Authentication with an 802.1x RADIUS Server” on page 319
z “Authentication with the Controller’s Internal Database” on page 333
In the following examples:
z Wireless clients associate to the ESSID WLAN-01.
z The following roles allow different networks access capabilities:
student
faculty
guest
system administrators
The examples show how to configure using the WebUI and CLI commands.
Authentication with an 802.1x RADIUS Server
z An EAP-compliant RADIUS server provides the 802.1x authentication. The RADIUS server administrator
must configure the server to support this authentication. The administrator must also configure the server to
all communications with the Dell controller.
Note: You can optionally assign a VLAN as part of a user role configuration. You should not use VLAN derivation if you configure
user roles with VLAN assignments
Table 54 VLAN Assignment for User and Machine Authentication
Machine Auth Status
User Auth
Status
Description VLAN Assigned
Failed Failed Both machine authentication and user
authentication failed. L2 authentication failed.
No VLAN
Failed Passed Machine authentication fails (for example, the
machine information is not present on the server)
and user authentication succeeds.
VLAN configured in the
virtual AP profile
Passed Failed Machine authentication succeeds and user
authentication has not been initiated.
VLAN configured in the
virtual AP profile
Passed Passed Both machine and user are successfully
authenticated.
Derived VLAN. Otherwise,
VLAN configured in the
virtual AP profile.