Specifications
About AAA for Network Users
17-6 Configuring AAA for Network Users
Thedefaultwell‐knownpasswordisEnterasysbutisconfigurable.(Thesamepassword
appliestoMACusers.)
Ifthelast‐resortauthenticationrulematchesonSSIDany,whichisawildcardthatmatcheson
anySSIDstring,theRADIUSserversorlocaldatabasemusthaveuserlast‐resort‐any,exactly
as
spelledhere.
Authorization
Iftheuserisauthenticated,MSSthencheckstheRADIUSserverorlocaldatabase(thesameplace
MSSlookedforuserinformationtoauthenticatetheuser)fortheauthorizationattributesassigned
totheuser.Authorizationattributesspecifythenetworkresourcestheusercanaccess.
TheonlyrequiredattributeistheVirtual
LAN(VLAN)nameonwhichtoplacetheuser.RADIUS
andMSShaveadditionaloptionalattributes.Forexample,youcanprovidefurtheraccesscontrols
byspecifyingthetimesduringwhichtheusercanaccessthenetwork,youcanapplyinbound and
outboundaccesscontrollists(ACLs)totheuser’straffic,
andsoon.
ToassignattributesontheRADIUSserver,usethestandardRADIUSattributessupportedonthe
server.ToassignattributesintheRoamAboutswit ch’slocaldatabase,usetheMSSvendor‐specif ic
attributes(VSAs).
TheRADIUSattributessupportedbyMSSaredescribedinAppendix C,SupportedRADIUS
Attributes.
MSSprovidesthe
followingVSAs,whichyoucanassigntousersconfiguredinthelocaldatabase
oronaRADIUSserver:
•Encryption‐Type—Specifies thetypeofencryptionrequiredforaccessbytheclient.Clients
whoattempttouseanunauthorizedencryptionmethodarerejected.
•End‐Date—Dateandtimeafterwhichtheuserisno
longerallowedtobeonthenetwork.
• Mobility‐Profile—Controls theRoa mAboutswitchportsausercanaccess.Forwirelessusers,
anMSSMobilityProfilespecifiestheAPsthroughwhichtheusercanaccessthenetwork.For
wiredauthenticationusers,theMobilityProfilespecifiesthewiredauthenticationports
throughwhichtheuser
canaccessthenetwork.
• SSID—SSIDtheuserisallowe d toaccessafterauthentication.
•Start‐Date—Dateand timeatwhichtheuserbecomeseligibletoaccessthenetwork.MSSdoes
notauthenticatetheuserunlesstheattempttoaccessthenetworkoccursatorafterthe
specifieddateandtime,butbefore
theend‐date(ifspecified).
•Time‐of‐Day—Day(s)andtime(s)duringwhichtheuserispermittedtologintothenetwork.
•URL—URLtowhichtheuserisredirectedaftersuccessfulWebAAA.
•VLAN‐Name—VLANtoplacetheuseron.
YoualsocanassignthefollowingRADIUSattributestousersconfiguredinthelocal
database.
•Filter‐Id—SecurityACLthatpermitsordeniestrafficreceived(input)orsent(output)the
RoamAboutSwitch.
•Service‐Type—Typeofaccesstheuserisrequesting,whichcanbenetworkaccess,
administrativeaccesstotheenabled(configuration)modeoftheMSSCLI,oradministrative
accesstothenonenabledmodeoftheCLI
•Session‐Timeout—Maximumnumberofsecondsallowedfortheuser’ssession.