Specifications
Configuring Web Web Portal WebAAA
17-26 Configuring AAA for Network Users
ThewebrulealsomustmatchontheSSIDtheuserwillusetoaccessthenetwork.Ifthe
userwillaccessthenetworkonawiredauthenticationport,therulemustmatchon
wired.
Toconfigureauthenticationrules,usethesetauthenticationwebcommand.
–WebPortalWebAAAmustbeenabled,
usingthesetweb‐portalcommand.Thefeatureis
enabledbydefault.
– Authenticationrules—AwebauthenticationrulemustbeconfiguredfortheWebAAA
users.ThewebrulemustmatchontheusernametheWebAAAuserwillenteronthe
WebAAAloginpage.(Thematchcanbeonausergloborindividual
username.)Theweb
rulealsomustmatchontheSSIDtheuserwillusetoaccessthenetwork.Iftheuserwill
accessthenetworkonawiredauthenticationport,therulemustmatchonwired.
Toconfigureauthenticationrules,usethesetauthenticationwebcommand.
–WebPortalWebAAAmustbe
enabled,usingthesetweb‐portalcommand.Thefeatureis
enabledbydefault.
Portal ACL and User ACLs
TheportalaclACL,whichMSScreatesautomatically,appliesonlywhenauser’ssessionisinthe
portalstate.Aftertheuserisauthenticatedandauthorized,theACLisnolongerapplicable.
Tomodifyauser’saccesswhiletheuserisstillbeingauthenticatedandauthorized,youcan
configureanotherACLand
mapthatACLinstea dtotheserviceprofileortheweb‐portal‐wired
user.Make suretousethecaptureoptionfortrafficyoudonotwanttoallow.EnterasysNetworks
recommendsthatyoudonotchangetheportalaclACL.LeavetheACLasabackupincaseyou
need
torefertoitoryouneedtouseitagain.
Forexample,ifyouwanttoallowtheusertoaccessacreditcardserverwhileMSSisstill
authenticatingandauthorizingtheuser,createanewACL,addACEsthatarethesameasthe
ACEsinportalacl,and
addanewACEbeforethelastone,toallowaccesstothecreditcardserver.
MakesurethelastACEintheACListhedenyACEthatcapturesalltrafficthatisnotallowedby
theotherACEs.
TomodifyaWebAAAuser’saccessaftertheuseris
authenticatedandauthorized,mapanACLto
theindividualWebAAAuser.ChangesyoumaketotheACLmappedtotheserviceprofileor
web‐portal‐wireduserdonotaffectuseraccessafterauthenticationandauthorizationare
complete.
Note: The filter-id attribute in a service profile applies only to authenticated users. If this attribute is
set in a service profile for an SSID accessed by Web-Portal users, the attribute applies only after
users have been authenticated. While a Web-Portal user is still being authenticated, the ACL set by
the web-portal-acl applies instead.