Specifications

Network User Configuration Scenarios
17-64 Configuring AAA for Network Users
During802.1XauthorizationforclientsatEXAMPLE\,MSSmustsearchfortheMobilityProfile
namedrosesprofile.Ifitisnotfound,theauthorizationfailsandclientswithusernameslike
EXAMPLE\joseandEXAMPLE\tamaraarerejected.
IfrosesprofileisconfiguredforEXAMPLE\usersonyourRoamAboutSwitch,MSSchecksitsport
list.If,forexample,thecurrentportforEXAMPLE\josesconnectionisonthelistofallowedports
specifiedinrosesprofile,theconnectionisallowedtoproceed.Iftheportisnotinthelist(for
example,EXAMPLE\joseisonport 12 ,whichisnotintheportlist),the a uthorization
failsand
clientEXAMPLE\joseisrejected.
TheMobilityProfilefeatureisdisabledbydefault.Youmust enable MobilityProfileattributeson
theRoamAboutSwitchtouseit.YoucanenableordisablethefeatureforthewholeRoamAbout
Switchonly.IftheMobilityProfilefeatureisdisabled,allMobilityProfileattributes
areignored.
ToputMobilityProfileattributesintoeffectonaRoamAboutSwitch,typethefollowing
command:
RBT-8100# set mobility-profile mode enable
success: change accepted.
TodisplaythenameofeachMobilityProfileanditsports,typethefollowingcommand:
RBT-8100# show mobility-profile
Mobility Profiles
Name Ports
=========================
roses-profile
AP 2
AP 3
AP 4
AP 7
AP 9
ToremoveaMobilityProfile,typethefollowing command:
clear mobility-profile name
Network User Configuration Scenarios
ThefollowingscenariosprovideexamplesofwaysinwhichyouuseAAAcommandstoconfigure
accessforusers:
•“GeneralUseofNetworkUserCommandsonpage 1765
•“EnablingRADIUSPassThroughAuthenticationonpage 1766
•“EnablingPEAPMSCHAPV2Authenticationonpage 1767
•“EnablingPEAPMSCHAPV2
Offloadonpage 1767
•“CombiningEAPOffloadwithPassThroughAuthenticationonpage 1768
•“OverridingAAAAssignedVLANsonpage 1768