Users Guide

Table Of Contents
Dell PowerConnect ArubaOS 5.0 | User Guide Roles and Policies | 287
4. Click the 802.1x Authentication Default Role drop-down list and select the desired user role for users who
have completed 802.1x authentication.
5. Click the MAC Authentication Default Role drop-down list and select the desired user role for clients who
have completed MAC authentication.
6. Click Apply.
In the CLI
aaa profile <profile>
initial-role <role>
dot1x-default-role <role>
mac-default-role <role>
For additional information on creating AAA profiles, see “AAA Profile Parameters” on page118.
User-Derived Role
The user role can be derived from attributes from the client’s association with an AP. You configure the user role
to be derived by specifying condition rules; when a condition is met, the specified user role is assigned to the
client. You can specify more than one condition rule; the order of rules is important as the first matching
condition is applied.
Table 57 describes the conditions for which you can specify a user role.
Note: User-derivation rules are executed before the client is authenticated.
Table 57 Conditions for User-Derived Role
Rule Type Condition Value
BSSID of AP to which client is associated One of the following:
z contains
z ends with
z equals
z does not equal
z starts with
MAC address (xx:xx:xx:xx:xx:xx)
User class identifier (option 77) returned by DHCP
server
equals string
Encryption type used by client One of the following:
z equals
z does not equal
z Open (no encryption)
z WPA/WPA2 AES
z WPA-TKIP (static or dynamic)
z Dynamic WEP
z WPA/WPA2 AES PSK
z Static WEP
z xSec
ESSID to which the client is associated One of the following:
z contains
z ends with
z equals
z does not equal
z starts with
z value of (does not take
string; attribute value is
used as role)
string