
166166 | Roles and Policies
Dell PowerConnect W-Series Aruba Instant 6.2.1.0-3.3 | User Guide
Configuring Machine and User Authentication Roles
You can assign different rights to clients based on whether their hardware device supports machine authentication.
Machine Authentication is only supported on Windows devices, so this can be used to distinguish between Windows
devices and other devices such as iPads.
You can create any of the following types of rules:
l Machine Auth only role - This indicates a Windows machine with no user logged in. The device supports machine
authentication and has a valid RADIUS account, but a user has not yet logged in and authenticated.
l User Auth only role - This indicates a known user or a non-Windows device. The device does not support
machine auth or does not have a RADIUS account, but the user is logged in and authenticated.
When a device does both machine and user authentication, the user obtains the default role or the derived role based
on the RADIUS attribute.
You can configure machine authentication with role-based access control using Instant UI or CLI.
In the Instant UI
To configure machine authentication with role-based access control, perform the following steps:
1. In the Access tab of the WLAN (New WLAN or Edit <WLAN-profile>) or Wired Network configuration (New
Wired Network or Edit Wired Network) window, under Roles, create Machine auth only and User auth
only roles.
2. Configure access rules for these roles by selecting the role, and applying the rule. For more information on
configuring access rules, see Configuring Access Rules on page 158.
3. Select Enforce Machine Authentication and select the Machine auth only and User auth only roles.
4. Click Finish to apply these changes.
In the CLI
To configure machine and user authentication roles for a WLAN SSID:
(Instant Access Point)(config)# wlan ssid-profile <SSID-Name>
(Instant Access Point)(SSID Profile<name>)# set-role-machine-auth <machine-authentication-
only> <user-authentication-only>
(Instant Access Point)(SSID Profile<name>)# end
(Instant Access Point)(SSID Profile<name>)# commit apply
To configure machine and user authentication roles for wired profile:
(Instant Access Point)(config)# wired-port-profile <profile-name>
(Instant Access Point)(wired ap profile<name>)# set-role-machine-auth <machine-authentication-
only> <user-authentication-only>
(Instant Access Point)(wired ap profile<name>)# end
(Instant Access Point)(wired ap profile<name>)# commit apply
Configuring Role Assignment Rules
This section describes the following procedures:
l Understanding Role Assignment Rules on page 167
l Extended Voice and Video Functionality on page 157
l Creating Role Assignment Rules on page 167
Komentarze do niniejszej Instrukcji