User`s manual
319
DWS-1008 User’s Manual
D-Link Systems, Inc.
Conguring AAA for Network Users
Overriding AAA-Assigned VLANs
The following example shows how to change the VLAN access of wireless users in an
organization housed in multiple buildings.
Suppose the wireless users on the faculty of a college English department have ofces
in building A and are authorized to use that building’s bldga-prof- VLANs. These users
also teach classes in building B. Because you do not want to tunnel these users back to
building A from building B when they use their wireless laptops in class, you congure the
location policy on the switch to redirect them to the bldgb-eng VLAN.
You also want to allow writing instructors normally authorized to use any -techcomm
VLAN in the college to access the network through the bldgb-eng VLAN when they are in
building B.
1. Redirect bldga-prof- VLAN users to the VLAN bldgb-eng:
DWS-1008# set location policy permit vlan bldgb-eng if vlan eq bldga-prof-*
2. Allow writing instructors from -techcomm VLANs to use the bldgb-eng VLAN:
DWS-1008# set location policy permit vlan bldgb-eng if vlan eq *-techcomm
3. Display the conguration:
DWS-1008# show location policy
Id Clauses
-----------------------------------------------------
1) permit vlan bldgb-teach if vlan eq bldga-prof-*
2) permit vlan bldgb-eng if vlan eq *-techcomm
4. Save the conguration:
DWS-1008 save cong
success: configuration saved.
(Footnotes)
1
1. EAP-MD5 does not work with Microsoft wired authentication client