Controller-less WLANs

Can we do dot1x authentication type based role derivation on Aruba Instant APs?

Environment : This article applies to all the IAPs running OS Version 6.1.3.4_3.1.0. Any OS version prior to 6.1.3.4_3.1.0 does not have this feature.

 

Role derivation has been supported on IAP since the initial versions. However, that was achieved only via Radius Attributes. 
A new feature was introduced in IAP version 6.1.3.4-3.1.0.0_35320 where in role derivation could be done based on- 

a. Dhcp-option 
b. Dot1x-authentication-type 

Following dot1x methods can be used to derive the user role: 

EAP-MD5 
EAP-TLS 
EAP-TTLS 
EAP-LEAP 
EAP-SIM 
EAP-AKA 
EAP-PEAP 
EAP-MSCHAPV2 
EAP-POTP 
EAP-OTP 
EAP-GTC 
EAP-PEAP-TLV 
EAP-FAST 
EAP-ZLXEAP 
EAP-SYMANTEC 

For complete configuration, please refer to the following article: 

000006715 - How to configure “dhcp-option” and “dot1x-authentication-type” based role derivation on Aruba Instant APs?

Version history
Revision #:
1 of 1
Last update:
‎06-29-2014 09:32 AM
Updated by:
 
Labels (1)
Contributors
Search Airheads
Showing results for 
Search instead for 
Did you mean: 
Is this a frequent problem?

Request an official Aruba knowledge base article to be written by our experts.