539| Remote AccessPoints DellPowerConnect W- Series ArubaOS 6.2 | UserGuide
4. From the Policy Type drop-downlist, select IPv4 Session.
5. To create the first rule:
a. Under Rules,click A dd.
b. UnderSource, select localip.
c. Under Destination, select any.
d. UnderActi on, select permit.
e. Click Apply.
Figure 174: EnableRest ricted Access to LD Homepage
In the CLI
Use the localipkeyword in t he userrole ACL.
By default,all users have an ACL entry o f type any any deny.This rule restricts access to all users. Whent he ACL
is configuredfor a user role, if a user any permitACL rule is configured, add a deny ACL beforet hat forlocalip
for restricting the userfrom accessing the LD homepage.
Example:
ip access-list session logon-control
user localip svc-http deny
user any permit
Configuring the AAA Profile fo r Tunneling
After you configurethe sessi on ACL, you definet heA AA profile usedfor split tunneling. When definingthe AA A
parameters,specify the previously configured user role that contains the session ACL used for split tunneling.
If you enable RADIUS accounting in the AAA profile, the controller sends a RADIUS accounting start record to the
RADIUS server when a user associates wit h the remote AP, and sends a stop record when the user logs out or is
deletedfrom the user database. If interim accounting is enabled, the controllersends updates at regular intervals.
Each interim record includes cumulativeuser stat istics, including received bytes and packets counters. For more
information on RADIUS accounting, see "RADIU S Accounting" on page 185
In the WebUI
1. Navigate to the Security >Authentication >AAA Profiles page. From the AAA Profiles Summary list, click
Add.
2. Enter the AAA profile name, then click Add.
3. Select the AAA profile that you just created.
a. For 802.1X Authenticati on Default Role, select the user role you previously configuredfor split tunneling,
then click Apply.
b. Underthe AA A profile that you created, locate 802.1x Authenticati on ServerGroup, and select the
authentication server groupt o use, then click Apply.
4. (Optional)To enable RADIUS acco unting: