Dell PowerConnect W-IAP175P Dell Instant 6.2.0.0-3.2.0.0 User Guide - Page 147

Creating Role Assignment Rules, MAC-Address Attribute, Attribute, Operator, contains, Is the role

Page 147 highlights

Creating Role Assignment Rules This section describes the rules for determining the role that is assigned for each authenticated client. NOTE: When Enforce Machine Authentication is enabled, both the device and the user must be authenticated for the role assignment rule to apply. To create role assignment rules for the user role: 1. Click New in the Role Assignment Rules section of the window. The default user role is the newly created user role. 2. Select the attribute from the Attribute drop-down list that the rule it matches against. The list of supported attributes includes RADIUS attributes (see "List of Supported VSA" on page 118), DHCP-Option, 802.1X-Authentication-Type, and MAC-Address. 3. Select the operator from the Operator drop-down list. The following types of operators are supported: l contains- To check if the attribute contains the operand value. l Is the role- To check if the role is same as the operand value. l equals- To check if the attribute is equal to the operand value. l not-equals- To check if the attribute is not equal to the operand value. l starts-with- To check if the attribute the starts with the operand value. l ends-with- To check if the attribute ends with the operand value. 4. Enter the string to match in the String text box. 5. Select the appropriate role from the Role drop-down list. 6. Click OK. Figure 107 - Creating Role Assignment Rules MAC-Address Attribute The first three octets in a MAC address are known as Organizationally Unique Identifier (OUI), and are purchased from the Institute of Electrical and Electronics Engineers, Incorporated (IEEE) Dell PowerConnect W-Series Instant Access Point 6.2.0.0-3.2.0.0 | User Guide 147 | Role Derivation

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296

Creating Role Assignment Rules
This section describes the rules for determining the role that is assigned for each authenticated
client.
NOTE: When Enforce Machine Authentication is enabled, both the device and the user must
be authenticated for the role assignment rule to apply.
To create role assignment rules for the user role:
1.
Click
New
in the
Role Assignment Rules
section of the window. The default user role is the
newly created user role.
2.
Select the attribute from the
Attribute
drop-down list that the rule it matches against. The
list of supported attributes includes RADIUS attributes (see
"List of Supported VSA" on page
118
), DHCP-Option, 802.1X-Authentication-Type, and MAC-Address.
3.
Select the operator from the
Operator
drop-down list. The following types of operators are
supported:
l
contains
— To check if the attribute contains the operand value.
l
Is the role
— To check if the role is same as the operand value.
l
equals
— To check if the attribute is equal to the operand value.
l
not-equals
— To check if the attribute is not equal to the operand value.
l
starts-with
— To check if the attribute the starts with the operand value.
l
ends-with
— To check if the attribute ends with the operand value.
4.
Enter the string to match in the
String
text box.
5.
Select the appropriate role from the
Role
drop-down list.
6.
Click
OK
.
Figure 107
- Creating Role Assignment Rules
MAC-Address Attribute
The first three octets in a MAC address are known as Organizationally Unique Identifier (OUI),
and are purchased from the Institute of Electrical and Electronics Engineers, Incorporated (IEEE)
Dell PowerConnect W-Series Instant Access Point
6.2.0.0-3.2.0.0
|
User Guide
147
|
Role Derivation