Aaa Tools For Network Users; Globs" And Groups For Network User Classification - 3Com 3CRWX120695A, 3CRWX440095A Configuration Manual

Wireless lan switch and controller
Table of Contents

Advertisement

AAA Tools for
Network Users
"Globs" and Groups
for Network User
Classification
automatically uses the same AAA method (RADIUS server group or
local database) for authorization that you define for a user's
authentication.
Local authorization control. You can override any AAA assignment
of VLAN or security ACL for individual network users on a particular
WX switch by configuring the location policy on the WX.
Accounting for tracking users and resources. Accounting collects
and sends information used for billing, auditing, and reporting — for
example, user identities, connection start and stop times, the number
of packets received and sent, and the number of bytes transferred.
You can track sessions through accounting information stored locally
or on a remote RADIUS server. As network users roam throughout a
Mobility Domain, accounting records track them and their network
usage.
Authentication verifies network user identity and is required before a
network user is granted access to the network. A WX switch
authenticates user identity by username-password matching, digital
signatures and certificates, or other methods (for example, by MAC
address).
You must decide whether to authenticate network users locally on the
WX, remotely via one or more external RADIUS server groups, or both
locally and remotely. (For server group details, see "Configuring RADIUS
Server Groups" on page 348.)
"Globbing" lets you classify users by username or MAC address for
different AAA treatments. A user glob is a string used by AAA and IEEE
802.1X or WebAAA methods to match a user or set of users. MAC
address globs match authentication methods to a MAC address or set of
MAC addresses. User globs and MAC address globs can make use of
wildcards. For details, see "User Globs, MAC Address Globs, and VLAN
Globs" on page 24.
A user group is a named collection of users or MAC addresses sharing a
common authorization policy. For example, you might group all users on
the first floor of building 17 into the group bldg-17-1st-floor, or group all
users in the IT group into the group infotech-people.

AAA Tools for Network Users

285

Advertisement

Table of Contents
loading

Table of Contents