Environment : This article applies to all the IAPs running OS Version 220.127.116.11_3.1.0. Any OS version prior to 18.104.22.168_3.1.0 does not have this feature.
Role derivation has been supported on IAP since the initial versions. However, that was achieved only via Radius Attributes.
A new feature was introduced in IAP version 22.214.171.124-126.96.36.199_35320 where in role derivation could be done based on-
Following dot1x methods can be used to derive the user role:
For complete configuration, please refer to the following article:
000006715 - How to configure “dhcp-option” and “dot1x-authentication-type” based role derivation on Aruba Instant APs?