307| Roles and Policies DellPowerConnect W- Series ArubaOS 6.2 | User Guide

RuleType Condition Value

lStaticWEP
lxSec
ESSID:Assign cli entto a role or V LANbased
uponthe ESSID to which the client is associated
Oneof the follow ing:
lcontains
lendswi th
lequals
ldoesnot equal
lstartswith
lvalueof (does not
take
string
; attribute
valuei s used as role)
string
Location:Assign client to a role or VLAN based
uponthe ESSID to which the client is associated
Oneof the follow ing:
lequals
ldoesnot equal
string
MACaddress of the cli ent Oneof the follow ing:
lcontains
lendswi th
lequals
ldoesnot equal
lstartswith
MACaddress (xx:xx:xx:xx:xx:xx)
Understanding Device Identif ication
The device identification feature allows you to assign a user roleor VLA N to a specific device type by identifying a
DHCP option and signature for that device. If yo u create a user rulewit h the DHCP-Option ruletype, the first two
charactersi n the Valuefield must represent the hexadecimal valueof the DHCP option t hat this ruleshould match,
while the rest of the charactersin the Value field indicate the DHCP signature the rule shouldmatch. To create a
rulethat matches DHCP optio n1 2 (host name),t hefirst t wo characterso ft hei n theValue field must be the
hexadecimalvalue of 12, which is 0C. To create a rule that matches DHCP opt ion 55, the first two characters in the
Valuefield must be t he hexadecimalvalue of 55, w hich is 37.
The followingtable describes some of t heD HCP options that are useful for assigning a user roleor VLA N.

DHCP Option Description HexadecimalEquivalent

12 Hostname 0C
55 Parameter Request List 37
60 VendorC lass Identifier 3C
81 Client FQDN 51
DHCP Option values
The device identification features in ArubaOScan also automatically identify different client device types and
operating systems by parsing the User-Agentstrings in the client’s HTTP packets. To enable this feature, select the
Device Type Classification option in the AP ’s AAA profile. For details, see "Device Type Classificati on" on page
319.
Configuring a User-derived VLAN in the WebUI
1. Navigate to the Configuration > Security > Authentication > Us er Rules page.