Overriding Or Adding Attributes Locally With A Location Policy; About The Location Policy - 3Com 3CRWX120695A, 3CRWX440095A Configuration Manual

Wireless lan switch and controller
Table of Contents

Advertisement

Overriding or
Adding Attributes
Locally with a
Location Policy
About the Location
Policy

Overriding or Adding Attributes Locally with a Location Policy

During the login process, the AAA authorization process is started
immediately after clients are authenticated to use the WX switch. During
authorization, MSS assigns the user to a VLAN and applies optional user
attributes, such as a session timeout value and one or more security ACL
filters.
A location policy is a set of rules that enables you to locally set or change
authorization attributes for a user after the user is authorized by AAA,
without making changes to the AAA server. For example, you might want
to enforce VLAN membership and security ACL policies on a particular
WX based on a client's organization or physical location, or assign a
VLAN to users who have no AAA assignment. For these situations, you
can configure the location policy on the switch.
Each WX switch can have one location policy. The location policy consists
of a set of rules. Each rule contains conditions, and an action to perform
if all conditions in the rule match.
The action can be one of the following:
Deny access to the network
Permit access, but set or change the user's VLAN assignment, inbound
ACL, outbound ACL, or any combination of these attributes
The conditions can be one or more of the following:
AAA-assigned VLAN
Username
MAP access port, Distributed MAP number, or wired authentication
port through which the user accessed the network
SSID name with which the user is associated
Conditions within a rule are ANDed. All conditions in the rule must match
in order for MSS to take the specified action. If the location policy
contains multiple rules, MSS compares the user information to the rules
one at a time, in the order the rules appear in the switch's configuration
file, beginning with the rule at the top of the list. MSS continues
comparing until a user matches all conditions in a rule or until there are
no more rules.
323

Advertisement

Table of Contents
loading

Table of Contents