Dell PowerConnect W Clearpass 100 Software Guía de usuario Pagina 168

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 296
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 167
168168 | Roles and Policies
Dell PowerConnect W-Series Aruba Instant 6.2.1.0-3.3 | User Guide
Access tab.
2. Under Role Assignment Rules, click New.
3. Select the attribute from the Attribute drop-down list that the rule it matches against. The list of supported
attributes includes RADIUS attributes, DHCP-Option, 802.1X-Authentication-Type, and MAC-Address. For
information on a list of RADIUS attributes, see RADIUS Server Authentication with VSA on page 119.
4. Select the operator from the Operator drop-down list. The following types of operators are supported:
l contains To check if the attribute contains the operand value.
l Is the role To check if the role is same as the operand value.
l equals To check if the attribute is equal to the operand value.
l not-equals To check if the attribute is not equal to the operand value.
l starts-with To check if the attribute the starts with the operand value.
l ends-with To check if the attribute ends with the operand value.
5. Enter the string to match in the String text box.
6. Select the appropriate role from the Role drop-down list.
7. Click OK.
When Enforce Machine Authentication is enabled, both the device and the user must be authenticated for
the role assignment rule to apply.
In the CLI
To configure role assignment rules for a WLAN SSID:
(Instant Access Point)(config)# wlan ssid-profile <SSID-Name>
(Instant Access Point)(SSID Profile<name>)# set-role <attribute>{{equals|not-equals|starts-
with|ends-with|contains}<operator><role>|value-of}
(Instant Access Point)(SSID Profile<name>)# end
(Instant Access Point)(SSID Profile<name>)# commit apply
To configure role assignment rules for a wired profile:
(Instant Access Point)(config)# wired-port-profile <profile-name>
(Instant Access Point)(wired ap profile<name>)# set-role <attribute>{{equals|not-equal|starts-
with|ends-with|contains}<operator> <role>| value-of}
(Instant Access Point)(wired ap profile<name>)# end
(Instant Access Point)(wired ap profile<name>)# commit apply
Configuring VLAN Assignment Rules
This section describes the following procedures:
l Understanding VLAN Assignment on page 168
l Configuring VLAN Derivation Rules on page 174
l Configuring a User Role for VLAN Derivation on page 175
Understanding VLAN Assignment
You can assign VLANs to a client based on the following configuration conditions:
l The default VLAN configured for the WLAN can be assigned to a client.
l If VLANs are configured for a WLAN SSID or an Ethernet port profile, the VLAN for client can be derived before
the authentication, from the rules configured for these profiles.
l If a rule derives a specific VLAN, it is prioritized over the user roles that may have a VLAN configured.
Vista de pagina 167
1 2 ... 163 164 165 166 167 168 169 170 171 172 173 ... 295 296

Comentarios a estos manuales

Sin comentarios