201| 802.1X Auth entication DellPowerConnect W- Series ArubaOS 6.2 | User Guide
server-cert <certificate>
ca-cert <certificate>
Configuring User a nd Machin e Authentica tion
Whena Windows device boot s, it logs onto the network domain using a machineaccount. Within the domain, the
device is authenticated beforeco mputergroup policies and software settings can be executed;t his processi s known
as

machineauthentication

. Machineauthenticatio nensures that only authorized devices are allowedon the network.
You can configure8 02.1x for both user and machine authentication (select the Enforce Machine Authentication
option described in Table 61). This tightens the authentication process further since both the device and userneed
to be authenticated.
Working with Ro leA ssignment with Machine Au thentication Ena bled
Whenyou enable machine authentication, there are two additi onalroles you can define in t he 802.1x authentication
profile:
lMachineauthenticat ion defaultmachine role
lMachineauthenticat ion defaultuser role
Whileyo ucan select the same role for both options, you should define the roles as per the polices that needt o be
enforced.Also, these roles can be different from the 802.1x authentication default roleconfigured in the AAA profile.
With machine authentication enabled,the assigned role depends upon the success or failureof the machine and user
authentications. In certain cases, the role that is ultimately assigned to a c lient can also dependupon attributes
returnedby the authenticati on servero r serverderivation rulesconfigured on the controller.
Table6 2 describes roleassi gnmentbased on the results of the machine and user authentications.

Machine

Auth

Status

User

Auth

Status

Description RoleAs signed

Failed Failed Bothmachine authentication and user
authenticationfailed. L2authentication
failed.
Norol e assigned. No accessto the network
allowed.
Failed Passed Machine authenticationfail s(for example,
themachi ne information is not presenton
theserver) and user authentication
succeeds.Server-derived rol es do not apply.
Machine authenticationdefault user role
configuredi n the802.1x authentication
profile.
Passed Failed Machine authenticationsucceeds and user
authenticationhas not been initiated. Server-
derivedrol es do not apply.
Machine authenticationdefault machi ne
role configured in the 802.1xauthentication
profile.
Passed Passed Bothmachine and user are successfully
authenticated.If there are server-derived
roles, therol e assignedvia the derivation
takeprecedence. Thi s is the
only
case
where server-derivedroles are appli ed.
Arole deri vedfrom the authentication
servertakes precedence. Otherwise, the
802.1xauthentication default role configured
in theAAA profile is assigned.

Table62 :

RoleAss ignmentfor User and MachineA uthentication

For example,if the following roles are configured:
l802.1x authentication default role (in AAA profile): dot1x_user
lMachineauthenticat ion defaultmachine role (in 802 .1x authentication profile): dot1x_mc