Environment : This article applies to all the IAPs running OS Version 188.8.131.52_3.1.0. Any OS version prior to 184.108.40.206_3.1.0 does not have this feature.
Role derivation has been supported on IAP since the initial versions. However, that was achieved only via Radius Attributes.
A new feature was introduced in IAP version 220.127.116.11-18.104.22.168_35320 where in role derivation could be done based on-
Following dot1x methods can be used to derive the user role:
For complete configuration, please refer to the following article:
000006715 - How to configure “dhcp-option” and “dot1x-authentication-type” based role derivation on Aruba Instant APs?