Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

802.1X default role.

This thread has been viewed 1 times
  • 1.  802.1X default role.

    Posted Nov 10, 2012 08:49 AM

    hi,

     

    just a simple question:

     

    Q: I do not have PEF license does this mean I can not see 802.1x default role option in AAA profile ?

     

    Q: without PEF my clients will have access only to (DHCP/DNS/HTTP/HTTPS) due to the guest role (which mean my IPT will not be able to work) ?



  • 2.  RE: 802.1X default role.

    EMPLOYEE
    Posted Nov 10, 2012 09:10 AM

    Without PEF, there is NO concept of roles.  If your clients pass 802.1x authentication they have no restrictions, whatsoever.

     



  • 3.  RE: 802.1X default role.

    Posted Nov 10, 2012 09:54 AM

    Thanks Joseph,

     

    I can not find dot1x default role in AAA profile is it because I do not have PEF license ?

     

    one more point for PSK authentication (only one key to be used by all wifi phones do I need to assign specific authentication profile of dot1x with EAP and its encapsulation) I do not belive so, therefore if I want to use PSK, I just do it in SSID and then I can leave Authentication profile in VAP empty ?

     

     



  • 4.  RE: 802.1X default role.

    EMPLOYEE
    Posted Nov 10, 2012 02:18 PM

    @Abi wrote:

    Thanks Joseph,

     

    I can not find dot1x default role in AAA profile is it because I do not have PEF license ?

     

    one more point for PSK authentication (only one key to be used by all wifi phones do I need to assign specific authentication profile of dot1x with EAP and its encapsulation) I do not belive so, therefore if I want to use PSK, I just do it in SSID and then I can leave Authentication profile in VAP empty ?

     

     


    There are no roles if there is no PEF license.  All users share a role.

     

    If you need to create a PSK network, you should use the WLAN/LAN wizard so you do not have to worry about profiles.