82 Configuring Web-based AAA for administrative and local access
NN47250-500 (Version 03.01)

Customizing Web-based AAA with “wildcards” and groups

“Wildcarding” lets you classify users by username or media access control (MAC) address for different Web-based
AAA treatments. A user wildcard is a string, possibly containing wildcards, for matching Web-based AAA and IEEE
802.1X authentication methods to a user or set of users. The WSS supports the following wildcard characters for user
wildcards:
Single asterisk (*) matches the characters in a username up to but not including a separator character, which can be
an at (@) sign or a period (.).
Double asterisk (**) matches all usernames.
In a similar fashion, MAC address wildcards match authentication methods to a MAC address or set of MAC addresses.
For details, see “User wildcards, MAC address wildcards, and VLAN wildcards” on page 47.
A user group is a named collection of users or MAC addresses sharing a common authorization policy. For example, you
might group all users on the first floor of building 17 into the group bldg-17-1st-floor, or group all users in the IT group
into the group infotech-people. Individual user entries override group entries if they both configure the same attribute.
(For information about configuring users and user groups, see “Adding and clearing local users for Administrative
Access” on page 84.)