Configuring AAA for Administrative and Local Access 61

Customizing AAA with “Wildcards” and Groups

“Wildcards” lets you classify users by username or media access control (MAC) address for different AAA treatments. A user wildcard is a string, possibly containing wildcards, for matching AAA and IEEE 802.1X authentication methods to a user or set of users. The WSS switch supports the following wildcard characters for user globs:

Single asterisk (*) matches the characters in a username up to but not including a separator character, which can be an at (@) sign or a period (.).

Double asterisk (**) matches all usernames.

In a similar fashion, MAC address globs match authentication methods to a MAC address or set of MAC addresses. For details, see “User Wildcards, MAC Address Wildcards, and VLAN Wildcards” on page 39.

A user group is a named collection of users or MAC addresses sharing a common authorization policy. For example, you might group all users on the first floor of building 17 into the group bldg-17-1st-floor, or group all users in the IT group into the group infotech-people. Individual user entries override group entries if they both configure the same attribute.

(For information about configuring users and user groups, see “Adding and Clearing Local Users for Administrative Access” on page 63.)

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 61
Image 61
Nortel Networks 2300 manual Customizing AAA with Wildcards and Groups