Nortel Networks 2300 Series manual Set mac-user, Clear location policy on Show location policy on

Models: 2300 Series

1 622
Download 622 pages 48.74 Kb
Page 205
Image 205

AAA Commands 205

Use inacl inacl-nameto filter traffic that enters the switch from users via an AP access port or wired authentication port, or from the network via a network port.

Use outacl outacl-nameto filter traffic sent from the switch to users via an AP access port or wired authentication port, or from the network via a network port.

You can optionally add the suffixes.in and.out to inacl-nameand outacl-nameso that they match the names of security ACLs stored in the local WSS database.

Examples The following command denies network access to all users at *.theirfirm.com, causing them to fail authorization:

WSS# set location policy deny if user eq *.theirfirm.com

The following command authorizes access to the guest_1 VLAN for all users who are not at *.wodefirm.com:

WSS# set location policy permit vlan guest_1 if user neq *.wodefirm.com

The following command authorizes users at *.ny.ourfirm.com to access the bld4.tac VLAN instead, and applies the security ACL tac_24 to the traffic they receive:

WSS# set location policy permit vlan bld4.tac outacl tac_24 if user eq *.ny.ourfirm.com

The following command authorizes access to users on VLANs with names matching bld4.* and applies security ACLs svcs_2 to the traffic they send and svcs_3 to the traffic they receive:

WSS# set location policy permit inacl svcs_2 outacl svcs_3 if vlan eq bldg4.*

The following command authorizes users entering the network on WSS ports 3 through 7 and port 12 to use the floor2 VLAN, overriding any settings from AAA:

WSS# set location policy permit vlan floor2 if port 3-7,12

The following command places all users who are authorized for SSID tempvendor_a into VLAN kiosk_1:

WSS# set location policy permit vlan kiosk_1 if ssid eq tempvendor_a

success: change accepted.

See Also

clear location policy on page 171

show location policy on page 215

set mac-user

Configures a user profile in the local database on the WSS for a user who can be authenticated by a MAC address, and optionally adds the user to a MAC user group.

(To configure a MAC user profile in RADIUS, see the documentation for your RADIUS server.)

Nortel WLAN—Security Switch 2300 Series Command Line Reference

Page 205
Image 205
Nortel Networks 2300 Series manual Set mac-user, WSS# set location policy deny if user eq *.theirfirm.com