4. Select thename to c onfigurethe server group.
5. UnderServers, click Edit for a configured server or click New to add a serverto the group.
lIf editing a configured server, select Trim FQDN, scroll right,and click Update Server.
lIf adding a new server,select a s erverfrom the drop-down menu, then select Trim FQDN, scroll right,and
click Add Server.
6. Click Apply.
Using the CLI
(host)(config) #aaa server-group corp-serv
auth-server radius-2 match-authstring contains abc.corpnet.com trim-fqdn
Configuring S erver-Derivation Rules
Whenyou c onfigurea server group, you can set the V LAN or role for clients based on attributes returned for the
client by the server duringauthenticati on. The serverderivatio n rulesapply to all serversi n the group.The user role
or VLAN assigned throughserver derivation rules takes precedenceover the default role andV LAN configuredfor the
authentication method.
NOTE:The authentication servers must be configured to return the attributesfor the clients during authentication. For instructions on
configuring theauthentication attributes in a Windows environment using IAS, refer to the documentation at
http://technet2.microsoft.com/windowsser ver/en/technologies/ias.mspx.
The serverrules are applied based on the first match principle. The first rule that is applicable for the server and the
attribute returnedis applied to t heclient and would be the only rule appliedfrom the server rules. These rulesare
applieduniformly across all servers in the server group.
Table5 5 describes the server ruleparameters you can configure.
Parameter Description
Role or VLAN Theserver derivation rules can be for either user role or VLAN assignment. With Role
assignment,a cl ient can be assigneda specific rol e basedon the attributes returned. In
caseof VLAN assignment, the client can be placed in a specific VLAN based on the
attributesreturned.
Attribute Thisi sthe attribute returned by the authentication serverthat is examined for
Operation
and
Operand
match.
Operation Thisi sthe match method by which the string in
Operand
ism atchedw ith theattribute value
returnedby the authentication server.
lcontains– The rule i sappl ied if and only if the attributevalue contains the string in
parameter
Operand.
lstarts-with– The rule is applied i fand onl yi fthe attribute value returned starts with the
stringin param eter
Operand.
lends-with– The rul e is applied if and only if the attributevalue returned ends with the
stringin param eter
Operand.
lequals– The rul e is applied if and only if the attributevalue returned equals the string
in parameter
Operand.
lnot-equals– The rule i sappl ied if and only if the attributevalue returned is not equal to
thestring in parameter
Operand.
lvalue-of– Thi s is a special condition. W hatthis i mplies is that the role or VLAN is set to
thevalue of the attribute returned. For this to be successful,the role and the VLAN ID

Table55 :

ServerRule ConfigurationParameters

DellPowerConnect W- Series ArubaOS 6.2 | User Guide AuthenticationServers | 182