Configuring Client Roles for AOS-CX

You can assign network access to clients using client roles. The network admin can create configuration profiles (roles) and associate them to clients. Client roles allow you to create and manage roles and attributes for the network.

The following are the maximum number of client roles that are supported on AOS-CX switches.

  • AOS-CX 4100i, 6100 switch series—32
  • AOS-CX 6200 switch series—64
  • AOS-CX 6300 switch series—10000

To create new client roles, complete the following steps:

  1. In the WebUI, select one of the following options:
    • To select a switch group in the filter:
      1. Set the filter to a group.

        The dashboard context for the group is displayed.

      2. Under Manage, click Devices > Switches.

        A list of switches is displayed in the List view.

      3. Click the AOS-CX or Config icon to view the switch configuration dashboard.
    •  To select a switch in the filter:
      1. Set the filter to Global or a group containing at least one switch.
      2. Under Manage, click Devices > Switches.

        A list of switches is displayed in the List view.

      3. Click an AOS-CX switch under Device Name.

        The dashboard context for the switch is displayed.

      4. Under Manage, click Device.

        The AOS-CX UI configuration page is displayed.

  2. Click Security > Client Roles.
  3. Under the Client Roles table, click + to create a new role.

    You can configure the following parameters.

    >

    Table 1: Client Roles Parameters

    Name

    Description

    Value

    Name

    Name of the role.

    This is a mandatory parameter.

    This parameters supports letters, numbers, and special characters.

    VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. mode

    VLAN mode of the role.

    Access or Trunk

    Default: Access

    VLAN

    VLAN ID of the role.

    Default: 1.

    Authentication mode

    Select either MD5 Message Digest 5. The MD5 algorithm is a widely used hash function producing a 128-bit hash value from the data input. (Message Digest) or SHA Secure Hash Algorithm. SHA is a family of cryptographic hash functions. The SHA algorithm includes the SHA, SHA-1, SHA-2 and SHA-3 variants. (Secure Hash Algorithm) as the authentication mode to provide secured access to the user.

    Client-Mode or Device-Mode

    Default: Client-Mode

    Trust mode

    Trust mode for the role.

     

    NONE, DSCP Differentiated Services Code Point. DSCP is a 6-bit packet header value used for traffic classification and priority assignment. , or COS

    Default: NONE

    Reauthentication period

    The time (in seconds) after which the switch enforces on a client to reauthenticate. The client remains authenticated while the reauthentication occurs.

    Default value is 30 seconds.

    PoE Power over Ethernet. PoE is a technology for wired Ethernet LANs to carry electric power required for the device in the data cables. The IEEE 802.3af PoE standard provides up to 15.4 W of power on each port. priority

    PoE priority configured on the port.

    Critical, High, or Low.

    Default: Low

    STP Spanning Tree Protocol. STP is a network protocol that builds a logical loop-free topology for Ethernet networks. admin edge port

    Enable or disable STP admin edge port for the role.

    By default, STP admin edge port is enabled.

    User-based tunnel

    Enable or disable user-based tunneling for the role.

    NOTE:  

    Move the toggle switch to the on position to enable.

    By default, it is disabled.

    Gateway cluster

    Name of the gateway cluster zone.

    NOTE: By default, the cluster zone name is default. You cannot change the gateway cluster name.

    This parameters supports letters, numbers, and special characters.

    Gateway Role

    Name of the gateway role for the client role.

    This parameter supports letters, numbers, and special characters.

  4. Click Save.

You cannot edit client roles.

Deleting Client Roles

To delete a client role, point to the row for the role, and click the delete icon.