Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 221

RADIUS Enforcement Profiles, Table 116

Page 221 highlights

l Generic Application Enforcement - Application specific enforcement profile with customization attribute-value pairs for authorization of generic applications. l CLI Based Enforcement - Enforcement profile that encapsulates CLI commands to be issued to the network device. The "Target Device" attribute specifies the device on which the "Command" attribute is executed. l Agent Enforcement - Enforcement profile that encapsulates attributes sent to Dell OnGuard agent. Attributes can be specified to bounce the client or to send a custom message to the client. l ClearPass Entity Update Enforcement - Post-authentication enforcement profile that can be filled with attributes to update the tag entries in endpoints and guest users. l Session Restrictions Enforcement - Post-authentication enforcement profile that can be filled with attributes to restrict users based on various factors such as bandwidth usage, active session count, and also terminate sessions when the limits are reached. Table 116: Add Enforcement Profile page Parameter Description Name/ Description Freeform label for enforcement profile. Type Auto-filled based on the selected template: RADIUS, TACACS, SNMP, Application, RADIUS_CoA Action Relevant only for RADIUS type enforcement profiles. Accept, Deny or Drop the request. Device Group List Associate the profile with pre-configured Device Groups. l Add New Device Group to add a new device group. l Add to add a device group from this drop-down list. l Remove, View Details, Modify to remove, view the details of, or modify the selected enforcement profile, respectively NOTE: This feature does not work with RADIUS CoA type Enforcement Profiles. The remaining Enforcement Profile tabs vary in content, depending on the Template Type (auto-specified in the Type field when a Template has been selected): l "RADIUS Enforcement Profiles " on page 221 l "RADIUS CoA Enforcement Profiles" on page 223 l "SNMP Enforcement Profiles " on page 224 l "TACACS+ Enforcement Profiles " on page 224 l "Application Enforcement Profiles " on page 226 l "CLI Enforcement Profile " on page 227 l "Agent Enforcement Profiles " on page 228 l Post Authentication Enforcement Profiles RADIUS Enforcement Profiles RADIUS Enforcement Profiles contain name/value pairings of attributes from the RADIUS dictionaries; in this editing context, Policy Manager displays only those attributes marked in the dictionary with the OUT or INOUT qualifier. The following figures illustrate rules for several sample profiles: Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 221

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

l
Generic Application Enforcement - Application specific enforcement profile with customization attribute-value
pairs for authorization of generic applications.
l
CLI Based Enforcement - Enforcement profile that encapsulates CLI commands to be issued to the network
device. The “Target Device” attribute specifies the device on which the “Command” attribute is executed.
l
Agent Enforcement - Enforcement profile that encapsulates attributes sent to Dell OnGuard agent. Attributes
can be specified to bounce the client or to send a custom message to the client.
l
ClearPass Entity Update Enforcement - Post-authentication enforcement profile that can be filled with
attributes to update the tag entries in endpoints and guest users.
l
Session Restrictions Enforcement - Post-authentication enforcement profile that can be filled with attributes to
restrict users based on various factors such as bandwidth usage, active session count, and also terminate sessions
when the limits are reached.
Table 116:
Add Enforcement Profile page
Parameter
Description
Name/
Description
Freeform label for enforcement profile.
Type
Auto-filled based on the selected template: RADIUS, TACACS, SNMP, Application, RADIUS_CoA
Action
Relevant only for RADIUS type enforcement profiles. Accept, Deny or Drop the request.
Device Group
List
Associate the profile with pre-configured Device Groups.
l
Add New Device Group
to add a new device group.
l
Add
to add a device group from this drop-down list.
l
Remove
,
View Details
,
Modify
to remove, view the details of, or modify the selected
enforcement profile, respectively
NOTE:
This feature does not work with RADIUS CoA type Enforcement Profiles.
The remaining
Enforcement Profile
tabs vary in content, depending on the
Template Type
(auto-specified in the
Type
field when a
Template
has been selected):
l
"RADIUS Enforcement Profiles " on page 221
l
"RADIUS CoA Enforcement Profiles" on page 223
l
"SNMP Enforcement Profiles " on page 224
l
"TACACS+ Enforcement Profiles " on page 224
l
"Application Enforcement Profiles " on page 226
l
"CLI Enforcement Profile " on page 227
l
"Agent Enforcement Profiles " on page 228
l
Post
Authentication
Enforcement
Profiles
RADIUS Enforcement Profiles
RADIUS Enforcement Profiles contain name/value pairings of attributes from the RADIUS dictionaries; in this
editing context, Policy Manager displays only those attributes marked in the dictionary with the
OUT
or
INOUT
qualifier.
The following figures illustrate rules for several sample profiles:
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
221