292CHAPTER 7: CONFIGURING AUTHENTICATION, AUTHORIZATION, AND ACCOUNTING PARAMETERS

The only required attribute is the Virtual LAN (VLAN) name on which to place the user. RADIUS and MSS have additional optional attributes. For example, you can provide further access controls by specifying the times during which the user can access the network, you can apply inbound and outbound access control lists (ACLs) to the user’s traffic, and so on.

To assign attributes on the RADIUS server, use the standard RADIUS attributes supported on the server. To assign attributes in the WX switch’s local database, use the MSS vendor-specific attributes (VSAs).

(The RADIUS attributes supported by MSS are described in an appendix in the Wireless LAN Switch and Controller Configuration Guide.)

MSS provides the following VSAs, which you can assign to users configured in the local database or on a RADIUS server:

„Encryption-Type— Specifies the type of encryption required for access by the client. Clients who attempt to use an unauthorized encryption method are rejected.

„End-Date— Date and time after which the user is no longer allowed to be on the network.

„Mobility-Profile— Controls the WX switch ports a user can access. For wireless users, an MSS Mobility Profile specifies the MAP access points through which the user can access the network. For wired authentication users, the Mobility Profile specifies the wired authentication ports through which the user can access the network.

„SSID — SSID the user is allowed to access after authentication.

„Start-Date— Date and time at which the user becomes eligible to access the network. MSS does not authenticate the user unless the attempt to access the network occurs at or after the specified date and time, but before the end-date (if specified).

„Time-of-Day— Day(s) and time(s) during which the user is permitted to log into the network.

„URL — URL to which the user is redirected after successful WebAAA.

„VLAN-Name— VLAN to place the user on.

You also can assign the following RADIUS attributes to users configured in the local database.

„Filter-Id— Security ACL that permits or denies traffic received by (input) or sent by (output) the user.

Page 292
Image 292
HP Manager Software manual