Creating Location Policy Rules - 3Com 3CRWX120695A Reference Manual

Wireless lan mobility system wireless lan switch manager
Hide thumbs Also See for 3CRWX120695A:
Table of Contents

Advertisement

340
C
7: C
HAPTER
ONFIGURING
Creating Location
Policy Rules
A
, A
UTHENTICATION
UTHORIZATION
During the authorization process, a VLAN is assigned as well as optional
user attributes, such as session timeout and any applicable security ACLs.
If you need to override the configured user attributes locally for a specific
WX, you can create a location policy, which consists of an ordered list of
location policy rules. A location policy rule specifies user access based on
a user glob, VLAN, and/or ports. (For more information about user globs,
see "Using User Globs and MAC Address Globs" on page 317.)
You can create one location policy per WX switch. Creating a location
policy allows you to override user attributes without making any changes
to the AAA server.
If a location policy exists, the WX compares configured user attributes
(the assigned VLAN, user glob, and port list) to the entries in the location
policy immediately after AAA authorization. Attributes are compared
against each entry in the order in which they appear in the location policy.
If a match is found, the parameters defined in the location policy override
previously configured user attributes. Any user attributes that are not
overridden by the location policy remain unchanged. If no match is
found, authorization proceeds as if the location policy does not exist.
Location policy rules are listed in the order created, unless you change the
order with the Modify Location Policy wizard. The order of rules in a
location policy is critical because a rule higher in the list is checked prior
to rules lower in the list. If the criteria for a rule are matched, the WX
stops comparing user attributes against the remaining location policy
rules in the list.
When creating a location policy rule, you specify one or more of the
following attributes, which are used to determine whether a location
policy is applied:
User glob
VLAN
Ports
To create a location policy rule
1 Access the WX Switch wizard for the WX switch. (See "Accessing the
Modify Switch Wizard" on page 185.)
2 Select AAA at the top of the wizard, if not already selected.
,
A
P
AND
CCOUNTING
ARAMETERS

Advertisement

Table of Contents
loading

This manual is also suitable for:

3crwx440095a

Table of Contents