673| Advanced Security DellPowerConnect W- Series ArubaOS 6.2 | User Guide
4. Co nfigurethe controller port to which the wired clients) are connected. Specify the VLAN to which the
authenticated xSecclients are assi gned.
For firewallrules to be enforced after client authentication, the port must be configuredas untrusted.
5. Co nfigurethe AAA profile to specify the 802.1x default user roleand the 802.1x authenticatio ns ervergroup.
6. Co nfigurethe wired authentication profile to use the AAA profile.
7. I nstalland set up the Odyssey Client on the wireless client.
Figure2 77 is an examplenetwork where a wired xSec client is assigned to the VLAN 20 and the userrole
“employee” upons uccessful802.1x authenticati on.Traffic between the controller and the xSec client is encrypted.
Figure 277: Wired xSec Client Example
The VLAN to which you assign an xSecclient must be a different VLAN from the VLAN that contains the
controllerport to which the wired xSec client or AP i s connected.
The followingsecti ons describehow to use the WebUI or CLI to configure the controllerpo rtt o which the wired
client is connected, the AAA profile, andt hew iredauthenticati on profilefor this example. Other chapters in this
manualdescribe the configuration of the user role, VLAN, authentication servers and server group,and 802.1x
authentication profile.
In the WebUI
1. N avigate to the Configuration > Networks > Ports page to co nfigurethe port to which the wired client(s) are
connected.
a. Click thepo rtthat you want to configure.
b. Make sure the Enable Port checkbox is selected.
c. For Enter VLAN(s), select the native VLAN on the port to ensure Layer-2 connectivity to the network. In
Figure2 77, this is VLAN 1.
d. For xSec VLAN, select the VLAN t o which authenticated usersare assigned from the drop-down menu.I n
Figure2 77, this is VLAN 20 .
e. Click Apply.
2. N avigate to the Configuration > Security > Authentication > AAA Profiles page to configure the AAA profile.
a. To create a new AAA profile, click Add.
b. Enter a name for the profile (forexample, xsec-wired), and click Add.
c. To configure theA AA profile, click on thenewly-created profile name.
d. For 80 2.1x Authentication Default Role, select a configured user role (for example,employee).
e. Click Apply.
f. In the AAA P rofilelist, select 80 2.1x Authentication Profile underthe AA A profiley ou configured.Select the
applicable80 2.1x authentication profile (for example,xsec-wir ed-dot1x). Click Apply.
g. In the AAA Profile list, select 802.1x Authentication Server Group underthe AA A profiley ou configured.
Select the applicableserver group (for example, xsec-svrs). Click Apply.
3. N avigate to the Configuration > Advanced Services > Wired Access page.
a. UnderWired Access AAA Profile, select the AAA profile you just configured.
b. Click Apply.