Dell PowerConnect W Clearpass 100 Software 3.7 Deployment Guide - Page 52
Attribute Tags, Attribute Authorization Conditions, Example: Time of Day Conditions, Save Changes
View all Dell PowerConnect W Clearpass 100 Software manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 52 highlights
When all the attributes have been added, click the Save Changes button to create this user role. You must click the Save Changes button before any of the changes you have made will take effect in the user role. A warning message will be displayed if you attempt to navigate away from the RADIUS Role Editor page while there are unsaved changes. Attribute Tags Certain attributes, principally those defined in RFC 2868, have a "tag" value associated with them. The tag value is a small number (1 to 31). To define a tag value for these attributes, prefix the value with the tag number surrounded by colons (:). For example, to set the Tunnel-Private-Group-Id attribute to 1000 with a tag of 1, type :1:1000 into the Value field. Attribute Authorization Conditions You are able to attach authorization conditions to attribute definitions. The choices for an attribute condition are: Always - the attribute will always be included in the RADIUS server's response. Never - the attribute is never included in the response. This option can be used to disable an attribute without deleting it. Enter condition expression... - the attribute will be included in the response only if the expression is true. See "Example: Time of Day Conditions" and "Example: Time-Based Authorization" in this chapter. Expressions must be entered as PHP code. Use condition expressions to perform authorization decisions at the time a RADIUS access request is performed. For example, you can alter the authorization for a user role depending on the time of day. It is also possible to refuse access when a certain condition is met. Several functions are available for use in attribute conditions. See "Standard RADIUS Request Functions" in the Reference chapter for detailed documentation about these functions. Example: Time of Day Conditions In this example, the Reply-Message attribute will be modified to provide a greeting to the guest that changes depending on the time of day. 1. Create a new role named Sample role. 52 | RADIUS Services Amigopod 3.7 | Deployment Guide