Specifications

About AAA for Network Users
17-6 Configuring AAA for Network Users
ThedefaultwellknownpasswordisEnterasysbutisconfigurable.(Thesamepassword
appliestoMACusers.)
IfthelastresortauthenticationrulematchesonSSIDany,whichisawildcardthatmatcheson
anySSIDstring,theRADIUSserversorlocaldatabasemusthaveuserlastresortany,exactly
as
spelledhere.
Authorization
Iftheuserisauthenticated,MSSthencheckstheRADIUSserverorlocaldatabase(thesameplace
MSSlookedforuserinformationtoauthenticatetheuser)fortheauthorizationattributesassigned
totheuser.Authorizationattributesspecifythenetworkresourcestheusercanaccess.
TheonlyrequiredattributeistheVirtual
LAN(VLAN)nameonwhichtoplacetheuser.RADIUS
andMSShaveadditionaloptionalattributes.Forexample,youcanprovidefurtheraccesscontrols
byspecifyingthetimesduringwhichtheusercanaccessthenetwork,youcanapplyinbound and
outboundaccesscontrollists(ACLs)totheuserstraffic,
andsoon.
ToassignattributesontheRADIUSserver,usethestandardRADIUSattributessupportedonthe
server.ToassignattributesintheRoamAboutswit ch’slocaldatabase,usetheMSSvendorspecif ic
attributes(VSAs).
TheRADIUSattributessupportedbyMSSaredescribedinAppendix C,SupportedRADIUS
Attributes.
MSSprovidesthe
followingVSAs,whichyoucanassigntousersconfiguredinthelocaldatabase
oronaRADIUSserver:
•EncryptionType—Specifies thetypeofencryptionrequiredforaccessbytheclient.Clients
whoattempttouseanunauthorizedencryptionmethodarerejected.
•EndDate—Dateandtimeafterwhichtheuserisno
longerallowedtobeonthenetwork.
MobilityProfile—Controls theRoa mAboutswitchportsausercanaccess.Forwirelessusers,
anMSSMobilityProfilespecifiestheAPsthroughwhichtheusercanaccessthenetwork.For
wiredauthenticationusers,theMobilityProfilespecifiesthewiredauthenticationports
throughwhichtheuser
canaccessthenetwork.
SSID—SSIDtheuserisallowe d toaccessafterauthentication.
•StartDate—Dateand timeatwhichtheuserbecomeseligibletoaccessthenetwork.MSSdoes
notauthenticatetheuserunlesstheattempttoaccessthenetworkoccursatorafterthe
specifieddateandtime,butbefore
theenddate(ifspecified).
•TimeofDay—Day(s)andtime(s)duringwhichtheuserispermittedtologintothenetwork.
•URLURLtowhichtheuserisredirectedaftersuccessfulWebAAA.
•VLANName—VLANtoplacetheuseron.
YoualsocanassignthefollowingRADIUSattributestousersconfiguredinthelocal
database.
•FilterId—SecurityACLthatpermitsordeniestrafficreceived(input)orsent(output)the
RoamAboutSwitch.
•ServiceType—Typeofaccesstheuserisrequesting,whichcanbenetworkaccess,
administrativeaccesstotheenabled(configuration)modeoftheMSSCLI,oradministrative
accesstothenonenabledmodeoftheCLI
•SessionTimeout—Maximumnumberofsecondsallowedfortheuserssession.