Access Role Profile

The Unified Profile Access Role Profile Screen displays all configured Access Role Profiles and is used to create, clone, edit, and delete Access Role Profiles. An Access Role Profile contains the various UNP properties (e.g., QoS Policy List attached to the UNP, Captive Portal Authentication) for users assigned to the profile. In a wireless-centric network, an Access Role Profile is considered as a user role with which every client in the wireless-centric network is associated.

Note: The Default WLAN Profile is a built-in profile for AOS Switches to set up edge infrastructure for a WLAN. Only the Auth Flag, Mobile Tag Status, and Policy List fields can be modified. However, you can clone the profile to create a new profile. Also note that the Default WLAN Profile cannot be deleted.

Creating an Access Role Profile

Click on the Add icon. Enter a Profile Name and configure the profile as described below, then click on the Create button. When you are finished, select the checkbox next to the profile and click on the Apply to Devices button to assign the profile to switches/wireless devices on the network.

Note: You can select a device type from the Highlight drop-down menu at the top of the screen to highlight configuration parameters for specific device types (6x, 7x, 8x). Selecting the "Highlight attributes applicable for 5x" option does not show a 5x indicator for any of the attributes, as only the profile name is applicable to 5x devices. In addition, 5x devices do not support dynamic VLAN configuration. Make sure the VLAN specified for the Access Role profile already exists.

Access Role Profile Attributes

General

Note: You can use a Unified Policy List or a Policy List created in PolicyView - Expert Mode in an Access Role Profile. If you use a Policy List in an Access Role Profile, you must apply the Access Role Profile to the same devices selected for the policies contained in the Policy List. Also note that policies created in PolicyView can only be applied to AOS Devices, not to APs.

Bandwidth Control Settings

Note: Applying Bandwidth Control Settings to devices that are running AOS 8.9R4 is supported only on the OS6860, OS6865, and OS6900.

Client Session Logging

Web Content Filtering (WCF)

Walled Garden

Client Isolation: Allowed Contacts List

Captive Portal Attributes

Advanced

Cloning an Access Role Profile

You can quickly create an Access Role Profile by selecting a profile in the Access Role Profile List, clicking on the Clone button and modifying the profile to create a new one. Click on the Copy button to create the new profile.

Assigning an Access Role Profile

When you click the Apply To Devices button, the Access Role Profile Assignments Wizard appears. Complete the screens as described below, then click on the Apply button.

Select Devices

Configure the mapping method and select devices.

Configure the Mapping Method

You can map the Access Role Profile to a specific VLAN or service. Select a Mapping Method, then make a selection from the drop-down menu. Note that you can only use one mapping method for a profile.

Dynamic VLAN Mapping

On 6.x Switches (running 6.7R08 and higher) and 8.x Switches (running 8.6R1 and higher) you can map an Access Role Profile to a dynamically-created VLAN. On 6.x Switches, you can map an Access Role Profile to a VLAN learned by a dynamic protocol (e.g., MVRP). The VLAN must be present on the switch. On 8.x Switches you can map an Access Role Profile to any VLAN even if the VLAN does not yet exist on the switch. The switch will create a UNP Dynamic VLAN. In both cases, the switch will decide whether it will permit the mapping.

Important Note: For dynamic VLAN mapping, you must first configure a Unified Access Global Configuration Setting with Global Dynamic UNP VLAN creation enabled, and assign that Global Configuration to network switches. Global Configurations are configured on the Unified Access Global Configuration Setting Screen (Unified Access - Unified Profile - Template - Global Configuration - Setting). See the Global Configuration Setting Screen online help for more information. You can also enable dynamic VLAN mapping on a device by editing a device on the Unified Access Unified Profile – Device Config - Global Configuration Setting Screen (Unified Access - Unified Profile – Device Config - Global Configuration - Setting). See the See the Device Config Global Configuration Setting Screen online help for more information.

Select Devices

After configuring the Mapping Method, click on the Devices ADD button and/or the AP Group ADD button to select devices. The device(s) will appear in the List of Selected Devices. If necessary, click on the Devices EDIT button and/or the AP Group EDIT button to add/remove devices from the list. See Common Errors When Assigning an Access Role Profile if you receive an error message when assigning a profile.

Note: If the Access Role Profile contains a Policy List, you must assign the profile to the same devices that are included in the Policies contained in the Policy List.

Note: You can also assign an Access Role Profile to a ClearPass Server. If a ClearPass Server is configured and connectivity established, the server will appear in the Device Selection Window in Blue.

Click on the Next button to configure a Period Policy.

Configure a Period Policy

You can specify the days and times during which a client can access devices. Select a Period Policy, then click on the Next button to configure a Location Policy.

Configure a Location Policy

You can specify the location of clients that can access devices. Select a Location Policy, then click on the Next button to review the configuration.

Review

Review the configuration and click on the Apply button to apply the policy to appendices Groups.

Common Errors When Assigning an Access Role Profile

The following common errors may be seen in the Results page when attempting to assign an Access Role Profile.Possible causes are provided for each.

Error Message

Possible Cause(s)

"Failed to apply Access Role Profile to VLAN ID 4094"

  • VLAN ID xx is not a standard VLAN.

"VLAN ID xx does not exist"

  • The VLAN specified must exist on the switch.

"VLAN ID xx is not a standard VLAN"

  • The specified VLAN should be a Standard VLAN.

Editing an Access Role Profile

Select the profile in the Access Role Profile List and click on the Edit icon to bring up the Edit Access Role Profile Screen. Edit the fields as described above then click on the Apply button to save the changes to the server. (Note that you cannot edit the Access Role Profile Name.) If the Access Role Profile has been applied to any devices, you must re-apply the profile to those devices. You can also go to the Device Config - Access Role Profile Screen to edit a profile on any device.

Note: The Default WLAN Profile is a built-in profile for AOS Switches to set up edge infrastructure for a WLAN. Only the Auth Flag, Mobile Tag Status, and Policy List fields can be modified. However, you can clone the profile to create a new profile.

Deleting an Access Role Profile

Select the profile in the Access Role Profile Screen and click on the Delete icon, then click OK at the confirmation prompt. This removes the profile from the server. If the profile has been assigned to any devices, go to the Device Config - Access Role Profile Screen to remove the profile from the device(s). Select the applicable device(s) in the Devices - Access Role Profile Table, click on the Delete icon, then click OK at the confirmation prompt.

Note: You cannot delete the Default WLAN Profile.