Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 229

Configuring Enforcement Policies, Table 124,

Page 229 highlights

Table 124: Post Authentication Enforcement Profiles Enforcement Profile Template Description A- ClearPassEntity Update Enforcement Enforcement profile template used to update tags in endpoints and guest users. Type is any endpoint, guest user, or a session update. Name is the name of an attribute associated with an endpoint, guest user, or a session update. If the type is session update, the tags are updated for either an endpoint or a guest user. Value is the value of the attribute. B-Session Restrictions Enforcement Enforcement profile template used to restrict users based on bandwidth usage and also disconnect users when the specified limits are crossed. Type is any post authentication check or session check that is applicable to the user. Name is the name of any specific check related the selected Type. Value is the value of the attribute. For example, if Bandwidth-Check is selected as the Type, you can select Start-Date from the Name drop-down list, and specify the start date in the Value field. If you have configured to disconnect users or devices that exceed bandwidth or session related limits, then the users or devices that exceed the specified limit get added to the blacklist user repository. You must add the Blacklist User Repository as an authentication source so that such users are denied access. For information on configuring Authentication Sources, refer to Adding and Modifying Authentication Sources Configuring Enforcement Policies One and only one Enforcement Policy can be associated with each Service. From the Services page (Configuration > Service), you can configure enforcement policy for a new service (as part of the flow of the Add Service wizard), or modify an existing enforcement policy (Configuration > Enforcement > Enforcement Policies, then click on its name in the Enforcement Policies listing page). Figure 199: Enforcement Policies Listing Page When you click Add Enforcement Policy, Policy Manager displays the Add Enforcement Policy wizard page: Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 229

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

Table 124:
Post Authentication Enforcement Profiles
Enforcement
Profile Template
Description
A—
ClearPassEntity
Update
Enforcement
Enforcement profile template used to update tags in endpoints and guest users.
Type
is any endpoint, guest user, or a session update.
Name
is the name of an attribute associated with an endpoint, guest user, or a session
update. If the type is session update, the tags are updated for either an endpoint or a guest
user.
Value
is the value of the attribute.
B—
Session
Restrictions
Enforcement
Enforcement profile template used to restrict users based on bandwidth usage and also
disconnect users when the specified limits are crossed.
Type
is any post authentication check or session check that is applicable to the user.
Name
is the name of any specific check related the selected
Type
.
Value
is the value of the attribute.
For example, if
Bandwidth-Check
is selected as the
Type
, you can select
Start-Date
from the
Name
drop-down list, and specify the start date in the
Value
field.
If you have configured to disconnect users or devices that exceed bandwidth or session related limits, then the users
or devices that exceed the specified limit get added to the blacklist user repository. You must add the
Blacklist User
Repository
as an authentication source so that such users are denied access. For information on configuring
Authentication Sources, refer to
Adding
and
Modifying
Authentication
Sources
Configuring Enforcement Policies
One and only one Enforcement Policy can be associated with each Service.
From the
Services
page (
Configuration > Service
), you can configure enforcement policy for a new service (as part
of the flow of the
Add Service
wizard), or modify an existing enforcement policy (
Configuration > Enforcement >
Enforcement Policies
, then click on its name in the
Enforcement Policies
listing page).
Figure 199:
Enforcement Policies Listing Page
When you click
Add Enforcement Policy
, Policy Manager displays the
Add Enforcement Policy
wizard page:
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
229