456Configuring AAA for Network Users

About the Location Policy

Each WSS switch can have one location policy. The location policy consists of a set of rules. Each rule contains condi- tions, and an action to perform if all conditions in the rule match.

The action can be one of the following:

Deny access to the network

Permit access, but set or change the user’s VLAN assignment, inbound ACL, outbound ACL, or any combination of these attributes

The conditions can be one or more of the following:

AAA-assigned VLAN

Username

AP access port, Distributed AP number, or wired authentication port through which the user accessed the network

SSID name with which the user is associated

Conditions within a rule are ANDed. All conditions in the rule must match in order for WSS Software to take the specified action. If the location policy contains multiple rules, WSS Software compares the user information to the rules one at a time, in the order the rules appear in the switch’s configuration file, beginning with the rule at the top of the list. WSS Software continues comparing until a user matches all conditions in a rule or until there are no more rules.

Any authorization attributes not changed by the location policy remain active.

320657-A

Page 456
Image 456
Nortel Networks 2300 manual About the Location Policy