Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Default user roles and the significance of each?

This thread has been viewed 44 times
  • 1.  Default user roles and the significance of each?

    Posted Feb 22, 2017 12:56 PM

    While configuring a AAA profile,

    The "initial role", "mac authentication default role", "dot1x authentication default role" could be mapped with one of the many default user roles viz:

    1. authenticated
    2. cpbase
    3. default-iap-user-role
    4. default-via-role
    5. default-vpn-role
    6. denyall
    7. guest
    8. guest-logon
    9. logon
    10. tpl-Authenticated
    11. voice

    However, I am failing to find the significance of each of these and its applicability.

    Do we have some study documentation giving proper insight on these profiles and its applicability?

     

     



  • 2.  RE: Default user roles and the significance of each?

    EMPLOYEE
    Posted Feb 22, 2017 01:02 PM

    The "initial role" is what you want a user to get if they do not authenticate.  If there is an Open SSID, a WEP SSID or  a WPA/2-PSK SSID the initial role is what they get upon association.  If the initial role is like an "allowall" role like authenticated, the user will simply be able to pass traffic without doing anything.  If the initial role is "logon", which is a captive portal role, the user will be presented with the captive portal upon successful association.

     

    The default 802.1x role is what a user gets if that user passes 802.1x authentication.  This of course can be overridden with radius attributes returned from the server, or server derivation rules.

     

    If mac authentication is enabled in the AAA profile, if the user passes mac authentication in combination with something else, the default mac authentication will be come the resulting user's role.

     

    I hope that makes sense..



  • 3.  RE: Default user roles and the significance of each?

    Posted Feb 27, 2017 08:52 AM

    For a listing of the default policies and roles and what is included as part of them; refer to the following section of the ArubaOS User Guide:   Basic System Defaults

     

     

     



  • 4.  RE: Default user roles and the significance of each?

    Posted Nov 08, 2019 10:57 AM

    Could I just check something - when using a dot1x VAP does the initial role have much effect? We have been using denyall but were advised to change to logon, I'm doing a bit of testing but I can't see how to actually view my current role - if I authenticate successfully then I appear in the user table with the authenticated role, but if I deliberately enter an incorrect password I don't know how to view what role I am in at that point. I'm not in the user table as I haven't authenticated, and the role isn't show in AP association table.

     

    Any ideas?

     

    Thanks

    Guy



  • 5.  RE: Default user roles and the significance of each?

    Posted Nov 08, 2019 11:20 AM

    Initial role is bit confusing to me. If you have authentication enabled, isn't the user denied access if they have wrong PSK or credentials? How does initial role work in that case?



  • 6.  RE: Default user roles and the significance of each?

    Posted Nov 08, 2019 11:39 AM

    Yes that's my understanding, but I'm not sure how this works with a dot1x SSID



  • 7.  RE: Default user roles and the significance of each?

    Posted Nov 08, 2019 11:44 AM
    Initial role is what you will get when doing psk. Mac-auth and/or 1x will give other roles. You make the default roles for each of these in the AAA profile which is what the client is given if the radius server returns only Radius Accept.
    If you fail the psk you will not get any role.


  • 8.  RE: Default user roles and the significance of each?

    Posted Nov 08, 2019 11:52 AM

    Thanks John,

     

    So up until the RADIUS accept is received is it true to say that the client doesn't have a role? In which case is it even necessary to have an initial role specified in dot1x AAA profiles (I'm assuming having one doesn't really break anything as we've had one specified for years, though it is the denyall role)?



  • 9.  RE: Default user roles and the significance of each?

    EMPLOYEE
    Posted Nov 09, 2019 09:20 AM

    The initial role is only used for a PSK, WEP or Open SSID, and is not used in a 802.1x transaction.

     

    Closing this thread because it is two years old.



  • 10.  RE: Default user roles and the significance of each?

    Posted Feb 27, 2017 05:06 AM

    Hello Adnan

     

    Did cjoseph answer your question? Or - was the question more related to the various User Roles themselves?

     

    Some information regarding the topic of User Roles

     

    Link to 6.4 Userguide about User Roles

    Slideshare link to a 2015 Atmosphere breakout session on the related topic Firewall