174
| Authentication and User Management
Aruba Instant 6.5.0.0-4.3.0.0 | User Guide
6. Click
Next
to define access rules, and then click
Finish
to apply the changes.
In the CLI
To enable MAC and 802.1X authentications for a wired profile:
(Instant AP)(config)# wired-port-profile <name>
(Instant AP)(wired ap profile "<name>")# type {<employee>|<guest>}
(Instant AP)(wired ap profile "<name>")# mac-authentication
(Instant AP)(wired ap profile "<name>")# dot1x
(Instant AP)(wired ap profile "<name>")# l2-auth-failthrough
(Instant AP)(wired ap profile "<name>")# auth-server <name>
(Instant AP)(wired ap profile "<name>")# server-load-balancing
(Instant AP)(wired ap profile "<name>")# radius-reauth-interval <Minutes>
(Instant AP)(wired ap profile "<name>")# end
(Instant AP)# commit apply
Configuring MAC Authentication with Captive Portal
Authentication
The following configuration conditions apply to MAC + captive portal authentication method:
l
If the captive portal splash page type is
Internal-Authenticated
or
External-RADIUS Server
, MAC
authentication reuses the server configurations.
l
If the captive portal splash page type is
Internal-Acknowledged
or
External-Authentication Text
and
MAC authentication is enabled, a server configuration page is displayed.
You can configure the MAC authentication with captive portal authentication for a network profile using the
Instant UI or the CLI.
In the Instant UI
1. Select an existing wireless or wired profile for which you want to enable MAC with captive portal
authentication. Depending on the network profile selected, the
Edit <WLAN-Profile>
or the
Edit Wired
Network
window is displayed.
To enable MAC authentication with captive portal authentication on a new WLAN SSID or wired profile, click the
Security
tab on the
New WLAN
window and the
New Wired Network
window.
2. On the
Security
tab, specify the following parameters:
a. Select
Enabled
from the
MAC authentication
drop-down list to enable MAC authentication for captive
portal users. If the MAC authentication fails, the captive portal authentication role is assigned to the
client.
b. To enforce MAC authentication, click the
Access
tab and select
Enforce MAC auth only role
check
box.
3. Click
Next
and then click
Finish
to apply the changes.
In the CLI
To configure MAC authentication with captive portal authentication for a wireless profile:
(Instant AP)(config)# wlan ssid-profile <name>
(Instant AP)(SSID Profile <name>)# type <guest>
(Instant AP)(SSID Profile <name>)# mac-authentication
(Instant AP)(SSID Profile <name>)# captive-portal {<type> [exclude-uplink <types>]|external
[Profile <name>] [exclude-uplink <types>]}
(Instant AP)(SSID Profile <name>)# set-role-mac-auth <mac-only>
(Instant AP)(SSID Profile <name>)# end
(Instant AP)# commit apply