Specifications

Assigning Authorization Attributes
RoamAbout Mobility System Software Configuration Guide 17-49
Assigning a Security ACL on a RADIUS Server
ToassignasecurityACLnameastheFilterIdauthorizationattributeofauserorgrouprecordon
aRADIUSserver,seethedocumentationforyourRADIUSserver.
Clearing a Security ACL from a User or Group
ToclearasecurityACLfromtheprofileofauser,MACuser,orgroupofusersorMACusersin
thelocalRoamAboutSwitchdatabase,usethefollowingcommands:
clear user username attr filter-id
clear usergroup groupname attr filter-id
clear mac-user username attr filter-id
clear mac-usergroup groupname attr filter-id
Ifyouhaveassignedbothanincomingandanoutgoingfiltertoauserorgroup,enterthe
appropriatecommandtwicetodeletebothsecurityACLs.Verifythedeletionsbyenteringthe
showaaacommandandcheckingtheoutput.
TodeleteasecurityACLfromausersconfigurationonaRADIUS
server,seethedocumentation
foryourRADIUSserver.
Assigning Encryption Types to Wireless Users
WhenauserturnsonawirelesslaptoporPDA,thedeviceattemptstofindanaccesspointand
formanassociationwithit.Becauseaccesspointssupporttheencryptionofwirelesstraffic,clients
canchooseanencryptiontypetouse.Youcanconfigureaccesspointstousetheencryption
algorithms
supportedbytheWiFiProtectedAccess(WPA)securityenhancementtotheIEEE
802.11wirelessstandard.(Fordetails,seeChapter 10,ConfiguringUserEncryption.)
Ifyouhaveconfiguredaccesspointstousespecificencryptionalgorithms,youcanenforcethe
typeofencryptionauserorgroupmusthavetoaccessthe
network.Whenyouassignthe
EncryptionTypeattributetoauserorgroup,theencryptiontypeortypesareenteredasan
authorizationattributeintotheuserorgrouprecordinthelocalRoamAboutSwitchdatabaseor
ontheRADIUSserver.EncryptionTypeisanEnterasysvendorspecificattribute(VSA).
Clientswhoattempttouseanunauthorizedencryptionmethodarerejected.
Assigning and Clearing Encryption Types Locally
TorestrictwirelessusesorgroupswithuserprofilesinthelocalRoamAboutSwitchdatabaseto
particularencryptionalgorithmsforaccessingthenetwork,useoneofthefollowingcommands:
set user username attr encryption-type value
set usergroup groupname attr encryption-type value
set mac-user username attr encryption-type value
set mac-usergroup groupname attr encryption-type value
MSSsupportsthefollow ingvaluesforEncryptionType,listedfrommost securetoleastsecure.
(Foruserencryptiondetails,seeChapter 10,ConfiguringUserEncryption.)
Encryption-Type Value Encryption Algorithm Assigned
1 Advanced Encryption Standard using Counter with Cipher Block Chaining
Message Authentication Code (CBC-MAC)—or AES_CCM.
2 Reserved.