Users Guide

Table Of Contents
12.Click Add.
13.To create the next rule:
a. Under Rules, click Add.
b. Under Source, select user.
c. Under Destination, select any.
d. Under Service, select any.
e. Under Action, select route and check src-nat.
f. Click Add.
14.Click Apply.
15.Click the User Roles tab.
a. Click Add to create and configure a new user role.
b. Enter the desired name for the role in the Role Name field.
c. Under Firewall Policies, click Add.
d. From the Choose from Configured Policies drop-down menu, select the policy you just configured.
e. Click Done.
16.Click Apply.
In the CLI
(host) (config) #ap system-profile <profile>
lms-preemption
lms-hold-down period <seconds>netdestination <policy>
network <ipaddr> <netmask>
network <ipaddr> <netmask>
(host) (config) #ip access-list session <policy>
any any svc-dhcp permit
any alias <name> any permit
user any any route src-nat
(host) (config) #user-role <role>
session-acl <policy>
When defining the alias, there are a number of other session ACLs that you can create to define the handling of
local traffic, such as:
(host) (config) #ip access-list session <policy>
user alias <name> any redirect 0
user alias <name> any route
user alias <name> any route src-nat
Configuring an ACL to Restrict Local Debug Homepage Access
A user in split or bridge role using a remote AP (RAP) can log on to the local debug (LD) homepage and perform
a reboot or reset operations. The LD homepage provides various information about the RAP and also has a
button to reboot the RAP. You can now restrict a RAP user from resetting or rebooting a RAP by using the
localip keyword in the in the user role ACL.
You will require the PEFNG license to use this feature. See Software Licenses on page 75 for more information on
licensing requirements.
Any user associated to that role can be allowed or denied access to the LD homepage. You can use the localip
keyword in the ACL rule to identify the local IP address on the RAP. The localip keyword identifies the set of
Dell Networking W-Series ArubaOS 6.5.x | User Guide Remote Access Points | 710