215| 802.1X Authentication DellPowerConnect W- Series ArubaOS 6.2 | UserGuide
Configuring 802.1x Auth entication
An AAA profile specifies the 802.1x authentication profile and 802.1x server group to be used for authenticating
clients for a WLAN. The AAA profile also specifies t he defaultuser role for 802.1x authenticati on.
For this example,y ou enableboth 802.1x authenticati on and termination on the controller.
In the WebUI
1. Navigate to the Configuration > Security > Authentication > L2 A uthentication page. In the profiles list,
select 802.1x Authentication Profile.
a. In the Instance list, enter dot1x, then click Add.
b. Selectthe dot 1x profiley ou just created.
c. Select Termination.
NOTE:The defaults for EAP Method and Inner EAP Method are EAP-PEAP and EAP-MSCHAPv2, respectively.
d. ClickA pply.
2. Select theA AA Profiles tab.
a. In the AAA Profiles Summary, click Add to add a new profile.
b. Enter aaa_dot1x, then click Add.
c. Select the aaa_dot1x profile you just created.
d. For8 02.1x Authentication Default Role, select faculty.
e. Click Apply.
3. In the Profiles list (under the aaa_dot1x profile you just created), select 802 .1x Authentication Profile.
a. Select the dot1x profile fromthe 80 2.1x Authentication Profile drop-downmenu.
b. ClickA pply.
4. In the Profiles list (under the aaa_dot1x profile you just created), select 802 .1x Authentication Server Group.
a. Select the internal server group.
b. ClickA pply.
In the CLI
(host)(config) #aaa authentication dot1x dot1x
termination enable
(host)(config) #aaa profile aaa_dot1x
d>ot1x-default-role student
authentication-dot1x dot1x
d>ot1x-server-group internal
Configuring V LANs
In this example, wireless clients are assigned to either VLAN 60 or 61 while guest users are assigned to VLAN 63.
VLANs 60 and 61 split users into smaller IP subnetworks, improving performance by decreasing broadcast traffic.
The VLANs are internal to the Dell controller only and do not extend into other parts of the wired network. The
clients’ default gateway is the Dell controller, which routes traffic out to the 10.1.1.0 subnetwork.
You configurethe V LANs, assign IP addresses to each VLAN, and establish the “ helperaddress” to which client
DHCP requests are forwarded.