Specifications
RoamAbout Mobility System Software Command Line Reference 8-41
Bydefault,usersarepermittedVLANaccessand assignedsecurityACLsaccordingtotheVLAN‐
NameandFilter‐Idattrib utesappliedtotheusersduringnormalauthenticationand
authorization.
Mode
Enabled.
Usage
OnlyasinglelocationpolicyisallowedperRAS.Onceconfigured,thelocationpolicybecomes
effectiveimmediately.Todisablelocationpolicyoperation,usetheclearlocationpolicy
command.
ConditionswithinaruleareANDed.AllconditionsintherulemustmatchinorderforMSSto
takethespecifiedaction.If
thelocationpolicycontainsmultiplerules,MSScomparestheuser
informationtotherulesoneatatime,intheordertherulesappearintheswitch’sconfiguration
file,beginningwiththeruleatthetopofthelist.MSScontinuescomparinguntilausermatchesall
conditionsinarule
oruntiltherearenomorerules.
vlanoperator
vlan‐glob
VLAN‐NameattributeassignedbyAAAandconditionbywhichto
determineifthelocationpolicyruleapplies.Replaceoperatorwithoneofthe
followingoperands:
• eq—AppliesthelocationpolicyruletoallusersassignedVLAN names
matchingvlan‐glob.
• neq—AppliesthelocationpolicyruletoallusersassignedVLANnames
notmatchingvlan‐glob.
Forvlan‐glob,specifyaVLANname,usethedouble‐asteriskwildcard
character(**)tospecifyallVLANnames,orusethesingle‐asteriskwildcard
character(*)tospecifyasetofVLANnames
uptoorfollowing thefirst
delimitercharacter,eitheranatsign(@)oraperiod(.).(Fordetails,see
“VLANGlobs”onpage 1‐4.)
useroperator
user‐glob
Usernameandconditionbywhichtodetermineifthelocationpolicyrule
applies.Replaceoperatorwithoneofthefollowingoperands:
• eq
—Appliesthelocationpolicyruletoallusernamesmatchinguser‐glob.
• neq—Appliesthelocationpolicyruletoallusernamesnotmatchinguser‐
glob.
Foruser‐glob,specifyausername,usethedouble‐asteriskwildcardcharacter
(**)tospecifyallusernames,orusethesingle‐asteriskwildcardcharacter(*)
tospecify
asetofusernamesuptoorfollowingthefirstdelimitercharacter,
eitheranatsign(@)oraperiod(.).(Fordetails,see“UserGlobs”onpage 1‐3.)
before
rule‐number
Insertsthenewlocationpolicyruleinfrontofanotherruleinthe location
policy.Specifythenumber
oftheexistinglocationpolicyrule.(Todetermine
thenumber,usetheshowlocationpolicycommand.)
modify
rule‐number
Replacestheruleinthelocationpolicywiththenewrule.Specifythenumber
oftheexistinglocationpolicyrule.(Todeterminethenumber,usetheshow
locationpolicycommand.)
portport‐list List
ofphysicalport(s)bywhichtodetermineifthelocationpolicyrule
applies.