Reference Guide

Table Of Contents
67 |aaa profile Dell PowerConnect ArubaOS 6.0 Command Line Interface | Reference Guide
Syntax
Usage Guidelines
The AAA profile defines the user role for unauthenticated users, the default user role for MAC or 802.1x
authentication, and user derivation rules. The AAA profile contains the authentication profile and authentication
server group.
Parameter Description Default
<profile> Name that identifies this instance of the profile. The name must be
1-63 characters.
“default”
authentication-dot1x
<dot1x-profile>
Name of the 802.1x authentication profile associated with the
WLAN. See “aaa authentication dot1x” on page 17.
authentication-mac <mac-
profile>
Name of the MAC authentication profile associated with the WLAN.
See “aaa authentication mac” on page 22.
clone <profile> Name of an existing AAA profile configuration from which
parameter values are copied.
dot1x-default-role <role> Configured role assigned to the client after 802.1x authentication. If
derivation rules are present, the role assigned to the client through
these rules take precedence over the default role.
NOTE: This parameter requires the PEFNG license.
guest
dot1x-server-group <group> Name of the server group used for 802.1x authentication. See “aaa
server-group” on page 70.
initial-role <role> Role for unauthenticated users. logon
mac-default-role <role> Configured role assigned to the user when the device is MAC
authenticated. If derivation rules are present, the role assigned to
the client through these rules take precedence over the default
role.
NOTE: This parameter requires the PEFNG license.
guest
mac-server- <group> group Name of the server group used for MAC authentication. See “aaa
server-group” on page 70.
no Negates any configured parameter.
radius-accounting <group> Name of the server group used for RADIUS accounting. See “aaa
server-group” on page 70.
rfc-3576-server <ip-addr> IP address of a RADIUS server that can send user disconnect and
change-of-authorization messages, as described in RFC 3576,
“Dynamic Authorization Extensions to Remote Dial In User Service
(RADIUS)”. See “aaa rfc-3576-server” on page 69.
NOTE: This parameter requires the PEFNG license.
sip-authentication-role
<role>
Configured role assigned to a session initiation protocol (SIP) client
upon registration.
NOTE: This parameter requires the PEFNG license.
guest
user-derivation-rules
<profile>
User attribute profile from which the user role or VLAN is derived.
wire-to-wireless-roam Keeps user authenticated when roaming from the wired side of the
network.
enabled
xml-api-server <ip-addr> IP address of a configured XML API server. See “aaa xml-api” on
page 85.
NOTE: This parameter requires the PEFNG license.