
ClearPass Guest 3.9 | Deployment Guide Operator Logins | 197
greater than – numerical value is greater than the match value
starts with – case-insensitive substring match at start of string
ends with – case-insensitive substring match at end of string
4. Select a Value. The Value field states what is to be matched, in this case CN=Administrators to look
for a specific group of which the user is a member.
5. Click the On Match drop-down list and select the action the system should take when there is a match.
Your options here are to:
Do nothing – makes no changes.
Assign fixed operator profile – assigns the selected Operator Profile to the operator
Assign attribute’s value to operator field – uses the value of the attribute as the value for an
operator field. This option can be used to store operator configuration details in the directory.
Assign custom value to operator field – uses a template to assign a value to a specific operator
field.
Apply custom processing – evaluates a template that may perform custom processing on the LDAP
operator.
Remove attribute from operator – removes the selected LDAP attribute from the operator.
6. Click the Operator Profile drop-down list and select the profile to be assigned if there is a rule match.
In the example shown above, if the Administrator group is matched, the Administrator profile is to be
assigned.
7. Select the Fallthrough check box if you want to use multiple translation rules. When you create
multiple rules, you can build a complete logical structure to perform any type of processing on the LDAP
attributes available in your directory.
8. Click Save Changes to save your rule settings.
The Administrator > Operator Logins > Translation Rules window shows a list of all configured
translation rules.
Translation rules are processed in order, until a matching rule is found that does not have the Fallthrough
field set.
Comentarios a estos manuales