d. For 802.1x Authentication Default Role, select a co nfigureduser role (for example, employee).
e. Click Apply.
f. In the A AA Profile list, select 802.1x Authentication Profile under the AAA profile you configured.Select the
applicable80 2.1x authentication profile (for example,xsec-wir eless-dot1x). Click Apply.
g. In the AAA Profile list, select 802.1x Authenticati on ServerGroup under the AAA profile you configured.
Select the applicableserver group (for example, xsec-svrs). Click Apply.
2. Navigate to the Configuration > Wireless >AP Configuration page. Select either the AP Groupor AP Specific
tab. Click Edit forthe applicable AP group nameo rAP name.
3. Under Profiles,select Wireless LAN, then select VirtualA P.
4. To create a new virtual AP profile, select NEW fromt heA dda profile drop-down menu. Enter the name fort he
virtualA P profile (for example,xsec-wir eless), and click Add.
a. In the Profile Details entry for the new virtual AP profile, select the AAA profile you previously configured.A
pop-upw indow displays the configuredA AA profile parameters.Click Apply in the pop-up window.
b. From the SSID profiledrop-down menu, select NEW. A pop-up window allows you to configure the SSID
profile.
c. Enter the name for the SSID profile (forexample, xsec-wireless).
d. Enter the Network Name fort heSSID (forexample, xsec-ap).
e. For Network Authentication, select xSec.
f. Click Apply in the pop-up window.
g. At the bottom of the Profile Details page, click Apply.
5. Click on the new virtual AP name in the Profiles list or i n Profile Details to display configuration parameters.
a. Make sure Virtual AP enable is selected.
b. For VLAN, enter the ID of the VLAN in which authenticated xSec clients are placed (forexample, 20).
c. Click Apply.
In the CLI
aaa profile xsec-wireless
authentication-dot1x xsec-wireless-dot1x
d>ot1x-default-role employee
d>ot1x-server-group xsec-svrs
wlan ssid-profile xsec-wireless
essid xsec-ap
opmode xSec
wlan virtual-ap xsec-wireless
vlan 20
aaa-profile xsec-wireless
ssid-profile xsec-wireless
Securing Wire d Clients
The followingare the basi c steps for configuring the controllerfor xSec wired clients:
1. Configure theV LAN to which the authenticated clients will be assigned. SeeNetw orkCo nfigurationP arameters
on page 108 for information.
This VLAN must have an IP interface,and is a different VLAN from the port’s “native” VLAN that provides
connectivity to the network.
2. Configure theuser role for the authenticated xSec clients. See Roles and Policies on page 296 for information.
3. Configure the servergroup that w illbe used t o authenticate clients using 802.1x. See Authenticatio n Serverson
page 168 for more information.
DellPowerConnect W- Series ArubaOS 6.2 | User Guide AdvancedSecurity | 672