Configuring 802.1x Security
109
Chapter 8
Enabling machine authentication gives rise to the following scenarios.
Before configuring 802.1x on the switch for machine authentication, you need to configure:
Machine
Auth
Status
User
Auth
Status
Description
Role
Typical Access
Policy
Failed
Failed
Both machine authentication and
user authentication failed. User
remain in the logon role
Logon
No access to
network
Failed
Passed
If the machine authentication
fails, due to reasons like
information not present on server
and user authentication succeeds,
the user will get the
User
Authentication Default Role
.
The derivation roles if present
will not
apply.
User
Authentication
Default Role
Limited access
depending on users
like guest.
Passed
Failed
If machine authentication
succeeds and user authentication
has not been initiated, the role
assigned would be the
Machine
Authentication Default Role.
The derivation rules if present
will not
apply
Machine
Authentication
Default Role
Access depending
on how secure the
machine is as far as
who access is
concerned.
Passed
Passed
In case both machine and user are
successfully authenticated, the
resultant role is the 802.1x
Default role
. In case of derivation
rules, the rules assigned to the
user via derivation rules will take
precedence over the default role.
This is the
only case
where
derivation rules would get
applied.
Default role
or
role assigned by
derivation rules.
Most secure since
both authentication
succeeded.
Permissions could
not depend purely
on the user
classification like
guest, employee,
admin etc.
Summary of Contents for AirOS v2.3
Page 10: ...x Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 28: ...18 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 42: ...32 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 76: ...66 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 92: ...82 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 107: ...Configuring the Captive Portal 97 Chapter 7...
Page 136: ...126 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 155: ...Configuring Virtual Private Networks 145 Chapter 9...
Page 156: ...146 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 199: ...System and Network Management 189 Chapter 11 5 Click Done to make the modification...
Page 212: ...202 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 246: ...236 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...
Page 254: ...244 Aruba AirOS Part 0500036 02 v2 3 User Guide January 2005...