Alcatel-Lucent IAP93 Betriebsanweisung Seite 178

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 335
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 177
Configuring Derivation Rules
AOS-W Instant allows you to configure role and VLAN derivation-rules. You can configure these rules to assign a
user role or VLAN to the clients connecting to an SSID or a wired profile.
Understanding Role Assignment Rule
When an SSID or wired profile is created, a default role for the clients connecting this SSID or wired profile is
assigned. You can assign a user role to the clients connecting to an SSID by any of the following methods. The role
assigned by some methods may take precedence over the roles assigned by the other methods.
RADIUS VSA Attributes
The user role can be derived from Alcatel-Lucent Vendor-Specific Attributes (VSA) for RADIUS server
authentication. The role derived from an Alcatel-Lucent VSA takes precedence over roles defined by other methods.
MAC-Address Attribute
The first three octets in a MAC address are known as Organizationally Unique Identifier (OUI), and are purchased
from the Institute of Electrical and Electronics Engineers, Incorporated (IEEE) Registration Authority. This identifier
uniquely identifies a vendor, manufacturer, or other organization (referred to by the IEEE as the “assignee”) globally
and effectively reserves a block of each possible type of derivative identifier (such as MAC addresses) for the
exclusive use of the assignee.
OAW-IAPs use the OUI part of a MAC address to identify the device manufacturer and can be configures to assign a
desired role for users who have completed 802.1X authentication and MAC authentication. The user role can be
derived from the user attributes after a client associates with an AP. You can configure rules that assign a user role
to clients that match a MAC address based criteria. For example, you can assign a voice role any client with a MAC
address starting a0:a1:a2.
Roles Based on Client Authentication
The user role can be the default user role configured for an authentication method, such as 802.1x authentication. For
each authentication method, you can configure a default role for clients who are successfully authenticated using
that method.
DHCP Option and DHCP Fingerprinting
The DHCP fingerprinting allows you to identify the operating system of a device by looking at the options in the
DHCP frame. Based on the operating system type, a role can be assigned to the device.
For example, to create a role assignment rule with DHCP option, select equals from the Operator drop-down list
and enter 370103060F77FC in the String text box. Since 370103060F77FC is the fingerprint for Apple iOS devices
such as iPad and iPhone, OAW-IAP assigns Apple iOS devices to the role that you choose.
Device DHCP Option DHCP Fingerprint
Apple iOS Option 55 370103060F77FC
Android Option 60 3C64686370636420342E302E3135
Blackberry Option 60 3C426C61636B4265727279
Windows 7/Vista Desktop Option 55 37010f03062c2e2f1f2179f92b
Table 31:
Validated DHCP Fingerprint
AOS-W Instant 6.3.1.1-4.0 | User Guide Roles and Policies | 178
Seitenansicht 177
1 2 ... 173 174 175 176 177 178 179 180 181 182 183 ... 334 335

Kommentare zu diesen Handbüchern

Keine Kommentare