Replace operator with one of the following operands:

 

eq—Applies the location policy rule to all users assigned VLAN names

 

matching vlan-glob.

 

neq—Applies the location policy rule to all users assigned VLAN

 

names not matching vlan-glob.

 

For vlan-glob, specify a VLAN name, use the double-asterisk wildcard

 

character (**) to specify all VLAN names, or use the single-asterisk

 

wildcard character (*) to specify a set of VLAN names up to or following

 

the first delimiter character, either an at sign (@) or a period (.). (For

 

details, see “VLAN Globs” on page 6.)

user operator user-glob

Username and condition by which to determine if the location policy

 

rule applies. Replace operator with one of the following operands:

 

eq—Applies the location policy rule to all usernames matching

 

user-glob.

 

neq—Applies the location policy rule to all usernames not matching

 

user-glob.

 

For user-glob, specify a username, use the double-asterisk wildcard

 

character (**) to specify all usernames, or use the single-asterisk

 

wildcard character (*) to specify a set of usernames up to or following

 

the first delimiter character, either an at sign (@) or a period (.). (For

 

details, see “User Globs” on page 6.)

before rule-number

Inserts the new location policy rule in front of another rule in the

 

location policy. Specify the number of the existing location policy rule.

 

(To determine the number, use the show location policy command.)

modify rule-number

Replaces the rule in the location policy with the new rule. Specify the

 

number of the existing location policy rule. (To determine the number,

 

use the show location policy command.)

port port-list

List of physical port(s) by which to determine if the location policy rule

 

applies.

Defaults: By default, users are permitted VLAN access and assigned security ACLs according to the VLAN-Name and Filter-Id attributes applied to the users during normal authentication and authorization.

Access: Enabled.

Usage: Only a single location policy is allowed per DWS-1008 switch. The location policy can contain up to 150 rules. Once configured, the location policy becomes effective immediately. To disable location policy operation, use the clear location policy command.

D-Link DWS-1008 CLI Manual

198

Page 201
Image 201
D-Link dws-1008 manual User operator user-glob, Before rule-number, Modify rule-number