Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 223

RADIUS CoA Enforcement Profiles, Table 117

Page 223 highlights

Table 117: RADIUS Enforcement Profile (Attributes tab) Enforcement Profile Template Description A- VLAN Enforcement Enforcement profile template to set IETF RADIUS standard VLAN attributes. B-Filter ID Based Enforcement Enforcement profile template to set IETF RADIUS standard filter ID attribute. C-Cisco Downloadable ACL Enforcement Enforcement profile template for Cisco IOS downloadable ACLs. D-Cisco Web Authentication Enforcement Enforcement profile template to set Cisco Web Authentication ACLs. E-(Generic) RADIUS-Based Authentication Type is any RADIUS vendor dictionary that is pre-packaged with Policy Manager, or imported by the Administrator. This field is prepopulated with the dictionary names. Name is the name of the attribute from the dictionary selected in the Type field. The attribute names are prepopulated from the dictionary. Value is the value of the attribute. If the value has prepopulated values is the dictionary, these appear in a drop-down list. Otherwise, you can enter freeform text. An Enforcement Profile can also contain dynamic values (as received in the request or authentication handshake, or as derived by the Policy Manager policy system). For example, to set the name of the VLAN to the name of the role, enter %{Tips:Role} as the value for RADIUS:IETF:Tunnel-Private-Group-Id. These dynamic values must be entered in the following format, without any spaces: %{namespace:attribute-name}. For convenience, the value field also has a drop down that contains all the authorization attributes. You can use these directly to assign dynamic values in the profile. Refer to figure above. RADIUS CoA Enforcement Profiles The RADIUS CoA tab contains a template type and the actions associated with that template type. The RADIUS CoA Enforcement Profile tab loads the CoA template attributes supported a specific template. Interface Description Select RADIUS CoA Template The supported template types are: l Cisco - Disable-Host-Port l Cisco - Bounce-Host-Port l Cisco - Reauthenticate-Session l HP - Change-VLAN l HP - Generic-CoA Attributes The RADIUS (standard and vendor-specific) shown here are base on the CoA Template selected from the drop down. Fill in values for all entries marked "Enter value here". The other pre-filled attributes must not be deleted, since the device requires these to be present. Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 223

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

Table 117:
RADIUS Enforcement Profile (Attributes tab)
Enforcement
Profile
Template
Description
A—
VLAN
Enforcement
Enforcement profile template to set IETF RADIUS standard VLAN attributes.
B—
Filter ID
Based
Enforcement
Enforcement profile template to set IETF RADIUS standard filter ID attribute.
C—
Cisco
Downloadable
ACL
Enforcement
Enforcement profile template for Cisco IOS downloadable ACLs.
D—
Cisco Web
Authentication
Enforcement
Enforcement profile template to set Cisco Web Authentication ACLs.
E—
(Generic)
RADIUS-Based
Authentication
Type
is any RADIUS vendor dictionary that is pre-packaged with Policy Manager, or imported by
the Administrator. This field is prepopulated with the dictionary names.
Name
is the name of the attribute from the dictionary selected in the Type field. The attribute
names are prepopulated from the dictionary.
Value
is the value of the attribute. If the value has prepopulated values is the dictionary, these
appear in a drop-down list. Otherwise, you can enter freeform text.
An Enforcement Profile can also contain dynamic values (as received in the request or
authentication handshake, or as derived by the Policy Manager policy system).
For example, to set the name of the VLAN to the name of the role, enter
%{Tips:Role}
as the
value for
RADIUS:IETF:Tunnel-Private-Group-Id
. These dynamic values must be
entered in the following format, without any spaces:
%{namespace:attribute-name}
.
For convenience, the value field also has a drop down that contains all the authorization
attributes. You can use these directly to assign dynamic values in the profile. Refer to figure
above.
RADIUS CoA Enforcement Profiles
The
RADIUS CoA
tab contains a template type and the actions associated with that template type.
The RADIUS CoA Enforcement
Profile
tab loads the CoA template attributes supported a specific template.
Interface
Description
Select
RADIUS
CoA
Template
The supported template types are:
l
Cisco - Disable-Host-Port
l
Cisco - Bounce-Host-Port
l
Cisco - Reauthenticate-Session
l
HP - Change-VLAN
l
HP - Generic-CoA
Attributes
The RADIUS (standard and vendor-specific) shown here are base on the CoA Template selected from
the drop down. Fill in values for all entries marked “Enter value here”. The other pre-filled attributes
must not be deleted, since the device requires these to be present.
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
223