Nortel Networks 2300 Series manual Filter-id, Mobility-profile on

Models: 2300 Series

1 622
Download 622 pages 48.74 Kb
Page 209
Image 209

AAA Commands 209

Table 1: Authentication Attributes for Local Users (continued)

Attribute

Description

Valid Value(s)

filter-id

(network access mode only)

Security access control list (ACL), to permit or deny traffic received (input) or sent (output) by the WSS.

(For more information about security ACLs, see “Security ACL Commands” on page 449.)

Name of an existing security ACL, up to

253 alphanumeric characters, with no tabs or spaces.

Use acl-name.into filter traffic that enters the switch from users via an AP access port or wired authentication port, or from the network via a network port.

Use acl-name.outto filter traffic sent from the switch to users via an AP access port or wired authentication port, or from the network via a network port.

 

 

Note: If the Filter-Id value returned through the

 

 

authentication and authorization process does not

 

 

match the name of a committed security ACL in

 

 

the WSS, the user fails authorization and is

 

 

unable to authenticate.

 

 

idle-timeout

This option is not implemented in the current WSS Software version.

 

 

 

mobility-profile

Mobility Profile attribute

Name of an existing Mobility Profile, which can

(network access mode

for the user. (For more

be up to 32 alphanumeric characters, with no tabs

only)

information, see set

or spaces.

 

mobility-profile on

 

 

page 204.)

Note: If the Mobility Profile feature is enabled,

 

 

and a user is assigned the name of a Mobility

 

Note: Mobility-Profile is a Profile that does not exist on the WSS, the user is

 

Nortel vendor-specific

denied access.

 

attribute (VSA). The

 

 

vendor ID is 562, and the

 

 

vendor type is 232.

 

 

 

 

Nortel WLAN—Security Switch 2300 Series Command Line Reference

Page 209
Image 209
Nortel Networks 2300 Series manual Filter-id, Mobility-profile on