Specifications

Configuring Last-Resort Access
17-36 Configuring AAA for Network Users
Configuring Last-Resort Access
Userswhoarenotauthenticatedandauthorizedby802.1XmethodsoraMACaddresscangain
limitedaccesstothenetworkasguestusers.Youcanoptionallyconfigureaspecialusername
calledlastresortwired(forwiredauthenticationaccess)orlastresortssid,wheressidistheSSID
requestedby
theuser.TomatchonthewildcardSSIDnameany,configureuserlastresortany,
exactlyasspelledhere.
Toconfigurealastresortauthenticationrule,usethefollowingcommand:
set authentication last-resort {ssid ssid-name | wired}
method1 [method2] [method3] [method4]
Examples
ToenablewirelessuserswhorequestSSIDguestssidtojointhenetworkonVLANk3,typethe
followingcommands:
RBT-8100# set authentication last-resort ssid guestssid local
success: change accepted
RBT-8100# set user last-resort-guestssid attr vlan-name k3
success: change accepted
LastresortusersconfiguredonaRADIUSserverrequireapassword.Specifytheauthorization
password(nopasswordbydefault.)Tochangethepassword,seeChangingtheMAC
AuthorizationPasswordforRADIUSonpage 1721.Thisprocedurealsoappliesforlastresort
users.
Toensurethatyourcommandsareconfigured,typethe
followingcommand:
RBT-8100# show aaa
...
set authentication last-resort ssid guestssid local
...
user last-resort-guestssid
vlan-name = k3
Note: Although MSS allows you to configure a user password for a last-resort user, the password
has no effect. Last-resort users can never access a RoamAbout Switch in administrative mode and
never require a password when authorized locally. However, if the last-resort user is authorized on a
RADIUS server, the server might require a password. In this case, use the authorization password
set on the RoamAbout switch, which is nopasswordby default.
Note: The fallthru authentication type must be set to last-resort. Otherwise, last-resort access is
disabled. The default fallthru authentication type for wireless access to an SSID is web. The default
for wired authentication access is none. (To change the fallthru authentication type for an SSID, see
Changing the Fallthru Authentication Type” on page 9-40. To change it for a wired authentication
port, see “Setting a Port for a Wired Authentication User” on page 4-3.