2. Click Add to add a new set of derivation rules. Enter a name for the set of rules, and click Add. The name
appearsi n the User Rules Summarylist.
3. In the User RulesSummary list, select the name of the rule set to configure rules.
4. Click Add to add a rule. For Set Type,select the VLA N nameo rI D from the VLANthe drop-down menu. (You
can select VLANt o created>erivatio nrules for setting the VLAN assigned to a client.)
5. Configurethe conditi on fort herule by setting the Rule Type, Condition, Value parameters and optional
description of the rule.See Table 82 for descripti ons of these parameters.
6. Select therole assigned to the client when this conditi on is met.
7. Click Add.
8. You can configureadditional rules for this rule set. Whenyou have added rules to the set, use the up or down
arrows in the Actions column to modify the order of the rules.(The first matching rule is applied.)
9. Click Apply.
10. (Optional) Ifthe rule uses the DHCP-Option condition, best practices is to enable the Enforce D HCP
parameterin the AP group’s AAA profile, which requiresusers to complete a DHCP exchange to obtain an IP
address.For details onconfiguring this parameter in an AAA profile, see"Configuring Authentication" on page
318.
Configuring a User-derived Role or VLAN in the CLI
(host)(config) #aaa derivation-rules user <name>
set role|vlan
condition bssid|dhcp-option|dhcp-option-77|encryption-type|essid|location|macaddr
contains|ends-with|equals|not-equals|starts-with|value-of <string>
set-value <role>
position <number>
See Table82 fordescriptions of these parameters.
User-Derived Role Example
The examplerule shown in Figure 83 below sets a user role for clients whose host name(DHCP option 12 ) has a
valueof 6 C6170746F70, which i s the hexadecimalequivalent of the ASCII string

laptop

. The first two digits in the
Valuefield are the hexadecimal value of 12 (which is 0C), followed by the specific signature to be matched.
NOTE:There are m anyonl ine tools available for converting ASCIItext to a hexadecimal string.
Figure 83: DHCP Option Rule
To identify DHCP strings used by an individual device, access the command-line interface in config mode and issue
the following commandt o include DHCP option values for DHCP-DISCOVER andDHCP-REQUEST frames in
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide Rolesand Policies | 308