2. In the Profiles list, expand the Stateful Kerberos Authentication Profile.
3. To define settings for an
existing
profile,click that profile name in the profiles list.
To create and define settings for a
new
StatefulKerberos Authenticati on profile,select an existi ngprofile, then
click the Save Asbutton in the right window pane. Enter a namefor the new profile in the entry field. at the top
of the right window pane.
4. Click the Default Role drop-down list,and select the role to be assigned to allusers after they complete stateful
Kerberosauthenticat ion.
5. Specify thet imeout periodfor authentication requests, from 1-20 seconds. Thedefault value is 10 seconds.
6. Click Apply.
7. In the Profiles list, select the Server Gr oup entry below the Stateful KerberosA uthentication profile.
8. Click the Server Group drop-down list and select the group of Windows serversyou want t o use forst ateful
Kerberosauthenticat ion.
9. Click Apply.
In the CLI
Use the followingco mmandsto c onfigurestateful Kerberos authentication via the command-line interface. Thefirst
set of commands defines the server used for Kerberos authentication, the second set adds that server to a server
group,and the third set of commands associates that s ervergroup with the stateful NTLM authentication profile
then definest he profilesett ings.
(host)(config)# aaa authentication-server windows <windows_server_name>
host <ipaddr>
enable
!
(host)(config)# aaa server-group group <server-group>
auth-server <windows_server_name>
!
(host)(config)# aaa authentication stateful-kerberos
default-role <role>
enable
server-group <server-group>
timeout <seconds>
Configuring WISPr Auth entication
A WISPr authentication profile includes parameters to define RADIUS attributes, the default role for authenticated
WISPr users,maximum numbers of authenticated failures and logon wait times. The WISPr-Location-ID sentfrom
the controllerto t heWISPr RA DIUS serveri s the concatenation of the ISO Country Code, E.164 Country Code,
E.164 Area Code and SSID/Zone parameters configuredi n this profile
The parametersto define WISPr RADIUS attributes are specific to theRADIUS server your ISP uses for WISPr
authentication; contact your ISP to determine these values. You can find a list of ISO and ITU country and area
codes at the ISO and ITU websitesg (www.iso.org)andhttp://www.itu.int.)
In the WebUI
This section describes how to create and configurea new instance of a WISPr authentication profile in the WebUI.
1. Navigate to the Configuration > Security > Authentication > L3 A uthentication page.
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide | 225