
179 | Roles and Policies AOS-W Instant 6.3.1.1-4.0 | User Guide
Device DHCP Option DHCP Fingerprint
Windows XP(SP3, Home,
Professional)
Option 55 37010f03062c2e2f1f21f92b
Windows Mobile Option 60 3c4d6963726f736f66742057696e646f777320434500
Windows 7 Phone Option 55 370103060f2c2e2f
Apple Mac OSX Option 55 370103060f775ffc2c2e2f
Creating a Role Derivation Rule
You can configure rules for determining the role that is assigned for each authenticated client.
When creating more than one role assignment rule, the first matching rule in the rule list is applied.
You can create a role assignment rules by using the AOS-W Instant UI or CLI.
In the AOS-W Instant UI
1. Navigate to the WLAN wizard or Wired settings window:
l To configure access rules for a WLANSSID, in the Network tab, click New to create a new network profile or
edit to modify an existing profile.
l To configure access rules for a wired profile, More>Wired. In the Wired window, click New under Wired
Networks to create a new network or click Edit to select an existing profile.
2. Click the Access tab.
3. Under Role Assignment Rules, click New. The New Role Assignment window allows you to define a match
method by which the string in
Operand
is matched with the attribute value returned by the authentication server.
4. Select the attribute from the Attribute drop-down list that the rule it matches against. The list of supported
attributes includes RADIUS attributes, dhcp-option, dot1x-authentication-type, mac-address, and mac-address-
and-dhcp-options. For information on a list of RADIUS attributes, see RADIUS Server Authentication with VSA
on page 136.
5. Select the operator from the Operator drop-down list. The following types of operators are supported:
l contains— The rule is applied only if the attribute value contains the string specified in
Operand
.
l Is the role— The rule is applied if the attribute value is the role.
l equals— The rule is applied only if the attribute value is equal to the string specified in
Operand
.
l not-equals— The rule is applied only if the attribute value is not equal to the string specified in
Operand
.
l starts-with— The rule is applied only if the attribute value starts with the string specified in
Operand
.
l ends-with— The rule is applied only if the attribute value ends with string specified in
Operand
.
l matches-regular-expression— The rule is applied only if the attribute value matches the regular expression
pattern specified in
Operand
. This operator is available only if the mac-address-and-dhcp-options attribute
is selected in the Attribute drop-down. The mac-address-and-dhcp-options attribute and matches-
regular-expression are applicable only for the WLAN clients.
6. Enter the string to match in the String text box.
7. Select the appropriate role from the Role drop-down list.
8. Click OK.
Kommentare zu diesen Handbüchern