Specifications

RoamAbout Mobility System Software Command Line Reference 8-41
Bydefault,usersarepermittedVLANaccessand assignedsecurityACLsaccordingtotheVLAN
NameandFilterIdattrib utesappliedtotheusersduringnormalauthenticationand
authorization.
Mode
Enabled.
Usage
OnlyasinglelocationpolicyisallowedperRAS.Onceconfigured,thelocationpolicybecomes
effectiveimmediately.Todisablelocationpolicyoperation,usetheclearlocationpolicy
command.
ConditionswithinaruleareANDed.AllconditionsintherulemustmatchinorderforMSSto
takethespecifiedaction.If
thelocationpolicycontainsmultiplerules,MSScomparestheuser
informationtotherulesoneatatime,intheordertherulesappearintheswitch’sconfiguration
file,beginningwiththeruleatthetopofthelist.MSScontinuescomparinguntilausermatchesall
conditionsinarule
oruntiltherearenomorerules.
vlanoperator
vlanglob
VLANNameattributeassignedbyAAAandconditionbywhichto
determineifthelocationpolicyruleapplies.Replaceoperatorwithoneofthe
followingoperands:
eq—AppliesthelocationpolicyruletoallusersassignedVLAN names
matchingvlanglob.
neq—AppliesthelocationpolicyruletoallusersassignedVLANnames
notmatchingvlanglob.
Forvlanglob,specifyaVLANname,usethedoubleasteriskwildcard
character(**)tospecifyallVLANnames,orusethesingleasteriskwildcard
character(*)tospecifyasetofVLANnames
uptoorfollowing thefirst
delimitercharacter,eitheranatsign(@)oraperiod(.).(Fordetails,see
VLANGlobsonpage 14.)
useroperator
userglob
Usernameandconditionbywhichtodetermineifthelocationpolicyrule
applies.Replaceoperatorwithoneofthefollowingoperands:
eq
—Appliesthelocationpolicyruletoallusernamesmatchinguserglob.
neq—Appliesthelocationpolicyruletoallusernamesnotmatchinguser
glob.
Foruserglob,specifyausername,usethedoubleasteriskwildcardcharacter
(**)tospecifyallusernames,orusethesingleasteriskwildcardcharacter(*)
tospecify
asetofusernamesuptoorfollowingthefirstdelimitercharacter,
eitheranatsign(@)oraperiod(.).(Fordetails,seeUserGlobsonpage 13.)
before
rulenumber
Insertsthenewlocationpolicyruleinfrontofanotherruleinthe location
policy.Specifythenumber
oftheexistinglocationpolicyrule.(Todetermine
thenumber,usetheshowlocationpolicycommand.)
modify
rulenumber
Replacestheruleinthelocationpolicywiththenewrule.Specifythenumber
oftheexistinglocationpolicyrule.(Todeterminethenumber,usetheshow
locationpolicycommand.)
portportlist List
ofphysicalport(s)bywhichtodetermineifthelocationpolicyrule
applies.