Dell PowerConnect W Clearpass 100 Software 3.9 Deployment Guide - Page 499

List of Standard Radius Attributes, Authentication Attributes

Page 499 highlights

Table 64 Rewrite Module Configuration Settings (Continued) Value Description module.attr_rewrite.name.searchfor = not set A regular expression to use when determining if the attribute should be matched. See "Regular Expressions" in this chapter for information about the supported syntax for regular expressions. module.attr_rewrite.name.replacewith = not set The replacement value which will be used for the attribute value, if the attribute matches the "searchfor" regular expression. Backreferences to the matching components of the "searchfor" regular expression are supported: %{0} will contain the string for the entire regular expression match, and %{1} through %{8} contain the contents of the 1st through the 8th matching parenthesized groups. If the "new_attribute" item is set to yes, then this value is used as the contents of a new attribute. module.attr_rewrite.name.ignore_case = no If set to yes, matches the "searchfor" regular expression in a case-insensitive way. The default behavior is to match case-sensitively. module.attr_rewrite.name.new_attribute = no If set to yes, a new attribute will be created, containing the value of the "replacewith" item. The new attribute will be added to the "searchin" item (packet, reply, proxy, proxy_reply or config). In this case, the "searchfor", "ignore_case" and "max_matches" items are ignored. module.attr_rewrite.name.max_matches = 10 The maximum number of regular expression matches to be processed for the attribute. module.attr_rewrite.name.append = no If set to yes, then the "replacewith" string will be appended to the original attribute value. The default of "no" causes the entire attribute value to be replaced. List of Standard Radius Attributes Authentication Attributes These are the attributes the NAS uses in authentication packets and expects to get back in authentication replies. These can be used in matching rules.  User-Name: This attribute indicates the name of the user to be authenticated or accounted. It is used in Access-Request and Accounting packets.  Password: This attribute indicates the password of the user to be authenticated, or the user's input following an Access-Challenge. It is only used in Access-Request packets.  CHAP-Password: This attribute indicates the response value provided by a PPP Challenge-Handshake Authentication Protocol (CHAP) user in response to the challenge. It is only used in Access-Request packets.  NAS-IP-Address: This attribute indicates the IP address of the NAS which is requesting authentication of the user. It is only used in Access-Request packets.  NAS-Port-Id: This attribute indicates the physical port number of the NAS which is authenticating the user. It is only used in Access-Request packets. Note that this is using "port" in its sense of a physical connection on the NAS, not in the sense of a TCP or UDP port number. ClearPass Guest 3.9 | Deployment Guide Reference | 499

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518

ClearPass Guest 3.9
|
Deployment Guide
Reference |
499
List of Standard Radius Attributes
Authentication Attributes
These are the attributes the NAS uses in authentication packets and expects to get back in authentication
replies. These can be used in matching rules.
User-Name
: This attribute indicates the name of the user to be authenticated or accounted. It is used in
Access-Request and Accounting packets.
Password
: This attribute indicates the password of the user to be authenticated, or the user’s input
following an Access-Challenge. It is only used in Access-Request packets.
CHAP-Password
: This attribute indicates the response value provided by a PPP Challenge-Handshake
Authentication Protocol (CHAP) user in response to the challenge. It is only used in Access-Request
packets.
NAS-IP-Address
: This attribute indicates the IP address of the NAS which is requesting authentication
of the user. It is only used in Access-Request packets.
NAS-Port-Id
: This attribute indicates the physical port number of the NAS which is authenticating the
user. It is only used in Access-Request packets. Note that this is using “port” in its sense of a physical
connection on the NAS, not in the sense of a TCP or UDP port number.
module.attr_rewrite.
name
.searchfor
=
not set
A regular expression to use when determining if the attribute
should be matched.
See
“Regular Expressions”
in this
chapter for information about the supported syntax for regular
expressions.
module.attr_rewrite.
name
.replacewith
=
not set
The replacement value which will be used for the attribute
value, if the attribute matches the “searchfor” regular
expression.
Backreferences to the matching components of the
“searchfor” regular expression are supported:
%{0}
will
contain the string for the entire regular expression match, and
%{1}
through
%{8}
contain the contents of the 1
st
through the
8
th
matching parenthesized groups.
If the “new_attribute” item is set to yes, then this value is used
as the contents of a new attribute.
module.attr_rewrite.
name
.ignore_case
= no
If set to yes, matches the “searchfor” regular expression in a
case-insensitive way.
The default behavior is to match case-sensitively.
module.attr_rewrite.
name
.new_attribute
= no
If set to yes, a new attribute will be created, containing the
value of the “replacewith” item.
The new attribute will be
added to the “searchin” item (packet, reply, proxy, proxy_reply
or config).
In this case, the “searchfor”, “ignore_case” and
“max_matches” items are ignored.
module.attr_rewrite.
name
.max_matches
= 10
The maximum number of regular expression matches to be
processed for the attribute.
module.attr_rewrite.
name
.append
= no
If set to yes, then the “replacewith” string will be appended to
the original attribute value.
The default of “no” causes the entire attribute value to be
replaced.
Table 64
Rewrite Module Configuration Settings
(Continued)
Value
Description