Owners manual

Aruba Instant 6.4.0.2-4.1 | User Guide Authentication and User Management | 141
Chapter 11
Authentication and User Management
This chapter provides the following information:
l Managing IAP Users on page 141
l Understanding Authentication Methods on page 148
l Supported Authentication Servers on page 151
l Understanding Encryption Types on page 155
l Support for Authentication Survivability on page 157
l Configuring Authentication Servers on page 158
l Configuring 802.1X Authentication for a Network Profile on page 164
l Configuring MAC Authentication for a Network Profile on page 166
l Configuring MAC Authentication with 802.1X Authentication on page 168
l Configuring MAC Authentication with Captive Portal Authentication on page 170
l Configuring WISPr Authentication on page 171
l Blacklisting Clients on page 172
l Uploading Certificates on page 174
Managing IAP Users
The IAP users can be classified as follows:
l Administrator— An admin user who creates SSIDs, wired profiles, DHCP server configuration parameters, and
manages the local user database. The admin users can access to the Virtual Controller Management User
Interface.
l Guest administrator A guest interface management user who manages guest users added in the local user
database.
l Administrator with read-only access The read-only admin user does not have access to the Instant CLI. The
Instant UI will be displayed in the read-only mode for these users.
l Employee users Employees who use the enterprise network for official tasks.
l Guest usersVisiting users who temporarily use the enterprise network to access the Internet.
The user access privileges are determined by IAP management settings in the AirWave Management client and
Aruba Central, and the type of the user. The following table outlines the access privileges defined for the admin user,
guest management interface admin, and read-only users.
User Category
Aruba Central or AirWave
Management Platform in Management
Mode
IAP in monitor mode or without AirWave
Management Platform or Aruba Central
administrator Access to local user database only Complete access to the IAP
read-only
administrator
No write privileges No write privileges
guest administrator Access to local user database only Access to local user database only
Table 28:
User Privileges