610 Configuring AAA for network users

NN47250-500 (Version 03.01)

About the location policy

Each WSS can have one location policy. The location policy consists of a set of rules. Each rule contains conditions, and
an action to perform if all conditions in the rule match. The location policy can contain up to 150 rules.
The action can be one of the following:
Deny access to the network
Permit access, but set or change the user’s VLAN assignment, inbound ACL, outbound ACL, or any combination of
these attributes
The conditions can be one or more of the following:
AAA-assigned VLAN
•Username
AP access port, Distributed AP number, or wired authentication port through which the user accessed the network
SSID name with which the user is associated
Day of the week or time of the day
Conditions within a rule are ANDed. All conditions in the rule must match in order for WSS Software to take the
specified action. If the location policy contains multiple rules, WSS Software compares the user information to the rules
one at a time, in the order the rules appear in the switch’s configuration file, beginning with the rule at the top of the list.
WSS Software continues comparing until a user matches all conditions in a rule or until there are no more rules.
Any authorization attributes not changed by the location policy remain active.
Note. It also helps local customization of the redirection URL.