Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 347

Variables, Table 222

Page 347 highlights

l Audit Namespace - Dictionaries in the audit namespace come pre-packaged with the product. Audit namespace has the notation Vendor:Audit, where Vendor is the name of the Company that has defined attributes in the dictionary. An example of a dictionary in the audit namespace is: Avenda Systems:Audit or Qualys:Audit. n Audit namespace appears when editing post-audit rules. (See " Audit Servers " on page 203for more information.) n Avenda Systems:Audit namespace appears when editing post-audit rules for NESSUS and NMAP audit servers. The attribute names and possible values with descriptions are shown in the table below: Table 222: Audit Namespace Attributes Attribute Name Values Audit-Status AUDIT_SUCCESS, AUDIT_INPROGRESS or AUDIT_ERROR Device-Type Type of device returned by an NMAP port scan Output-Msgs Network-Apps Mac-Vendor OS-Info Open-Ports The output message returned by Nessus plugin after a vulnerability scan String representation of the open network ports (http, telnet, etc.) Vendor associated with MAC address of the host OS information string returned by NMAP The port numbers of open applications on the host l Tacacs Namespace - Tacacs namespace has the attributes associated with attributes available in a TACACS+ request. Available attributes are AvendaAVPair, UserName and AuthSource. l Application Namespace - Application namespace has a name attribute. This attribute is an enumerated type currently containing the following string values: GuestConnect, Insight, Edge. Variables Variables are populated with the connection-specific values. Variable names (prefixed with % and enclosed in curly braces; for example, %{Username}") can be used in filters, role mapping, enforcement rules and enforcement profiles. Policy Manager does in-place substitution of the value of the variable during runtime rule evaluation. The following built-in variables are supported in Policy Manager: Table 223: Policy Manager Variables Variable Description %{attributename} attribute-name is the alias name for an attribute that you have configured to be retrieved from an authentication source. See "Adding and Modifying Authentication Sources " on page 127. % MAC address of client in aa:bb:cc:dd:ee:ff format {RADIUS:IETF:MAC- Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 347

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

l
Audit Namespace
- Dictionaries in the audit namespace come pre-packaged with the product. Audit namespace
has the notation Vendor:Audit, where Vendor is the name of the Company that has defined attributes in the
dictionary. An example of a dictionary in the audit namespace is: Avenda Systems:Audit or Qualys:Audit.
n
Audit namespace appears when editing post-audit rules. (See
" Audit Servers " on page 203
for more
information.)
n
Avenda Systems:Audit namespace appears when editing post-audit rules for NESSUS and NMAP audit
servers. The attribute names and possible values with descriptions are shown in the table below:
Table 222:
Audit Namespace Attributes
Attribute Name
Values
Audit-Status
AUDIT_SUCCESS, AUDIT_INPROGRESS or AUDIT_ERROR
Device-Type
Type of device returned by an NMAP port scan
Output-Msgs
The output message returned by Nessus plugin after a vulnerability scan
Network-Apps
String representation of the open network ports (http, telnet, etc.)
Mac-Vendor
Vendor associated with MAC address of the host
OS-Info
OS information string returned by NMAP
Open-Ports
The port numbers of open applications on the host
l
Tacacs Namespace
- Tacacs namespace has the attributes associated with attributes available in a TACACS+
request. Available attributes are AvendaAVPair, UserName and AuthSource.
l
Application Namespace
- Application namespace has a name attribute. This attribute is an enumerated type
currently containing the following string values: GuestConnect, Insight, Edge.
Variables
Variables are populated with the connection-specific values. Variable names (prefixed with % and enclosed in curly
braces; for example, %{Username}”) can be used in filters, role mapping, enforcement rules and enforcement profiles.
Policy Manager does in-place substitution of the value of the variable during runtime rule evaluation. The following
built-in variables are supported in Policy Manager:
Table 223:
Policy Manager Variables
Variable
Description
%{
attribute-
name
}
attribute-name
is the alias name for an attribute that you have configured to be
retrieved from an authentication source. See
"Adding and Modifying Authentication
Sources " on page 127
.
%
{RADIUS:IETF:MAC-
MAC address of client in aa:bb:cc:dd:ee:ff format
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
347