Creating the Faculty Role and Pol icy
The faculty policy is similar to the st udentpolicy , howeverfaculty members are allowed to use POP3 and SMTP for
VPN remote access from home. (Studentsare not permitted to use V PN remote access.) The faculty policy is
mappedt o the faculty user role.

Using the WebUI

1. Navigate to the Configuration > Security > Access Control > Policies page. Click Add to add the faculty
policy.
2. For Po licy Name, enter faculty.
3. For Po licy Type, select IPv4 Session.
4. Under Rules, click Add to add rules for the policy.
a. Under Source, select user.
b. Under Destination, select alias, then selectInt ernal Network.
c. U nderService, select service. I n the Service scrollinglist, select sv c-telnet.
d. Under Action, select drop.
e. Click A dd.
f. Repeat steps A-E to createrules for the following services: svc-ftp, svc-snmp, and svc-ssh.
5. Click Apply.
6. Select the User Roles tab. Click Add to create the faculty role.
7. For Role Name, enter faculty.
8. Under Firewall Policies, click Add. In Choose from Configured Policies, select the faculty policy yo u previously
created.Click D one.
In theCL I
(host)(config) #ip access-list session faculty
user alias “Internal Network” svc-telnet deny
user alias “Internal Network” svc-ftp deny
user alias “Internal Network” svc-snmp deny
user alias “Internal Network” svc-ssh deny
(host)(config) #user-role faculty
session-acl faculty
session-acl allowall
Creating the Guest Role and Pol icy
The guest policy permitso nlyaccess to the Internet (via HTTP or HTTPS) and only duringdaytime working hours.
The guest policy is mapped to the guest userrole.
In theWebUI
1. Navigate to the Configuration > Security > Access Control > Time Ranges page to definet heti me range
“working-hours”.Click Add.
a. For N ame,enter wor king-hours.
b. For Type, select Periodic.
c. Click A dd.
d. For Start Day, click W eekday.
e. For Start Time,enter 07:30.
f. For End Time, enter 17:00.
DellPowerConnect W- Series ArubaOS 6.2 | User Guide 802.1XAuthentication | 206