Overriding Or Adding Attributes Locally With A Location Policy; About The Location Policy - D-Link DWS-1008 - AirPremier MobileLAN Switch Product Manual

8 port 10/100 wireless switch with power over ethernet
Hide thumbs Also See for DWS-1008 - AirPremier MobileLAN Switch:
Table of Contents

Advertisement

Note. The keep-initial-vlan option does not apply to Web-Portal clients, Instead, VLAN assignment for
roaming Web-Portal clients automatically works the same way as when keep-initial-vlan is enabled. The
VLAN initially assigned to a Web-Portal user is not changed except by a location policy, AAA, or SSID
default setting on the roamed-to switch.
To enable keep-initial-vlan, use the following command:
set service-profile name keep-initial-vlan {enable | disable}
Enter this command on the switch that will be roamed to by users.
The following command enables the keep-initial-vlan option on service profile sp3:
DWS-1008# set service-profile sp3 keep-initial-vlan enable
success: change accepted.
Overriding or Adding Attributes Locally
During the login process, the AAA authorization process is started immediately after clients are
authenticated to use the switch. During authorization, MSS assigns the user to a VLAN and applies
optional user attributes, such as a session timeout value and one or more security ACL filters.
A location policy is a set of rules that enables you to locally set or change authorization attributes for a
user after the user is authorized by AAA, without making changes to the AAA server. For example, you
might want to enforce VLAN membership and security ACL policies on a particular switch based on a
client's organization or physical location, or assign a VLAN to users who have no AAA assignment. For
these situations, you can configure the location policy on the switch.
You can use a location policy to locally set or change the Filter-Id and VLAN-Name authorization
attributes obtained from AAA.
Each switch can have one location policy. The location policy consists of a set of rules. Each rule
contains conditions, and an action to perform if all conditions in the rule match. The location policy can
contain up to 150 rules.
The action can be one of the following:
• Deny access to the network
• Permit access, but set or change the user's VLAN assignment, inbound ACL, outbound
ACL, or any combination of these attributes
D-Link DWS-1008 User Manual
with a Location Policy

About the Location Policy



Advertisement

Table of Contents
loading

Table of Contents