Specifications
Overriding or Adding Attributes Locally with a Location Policy
17-52 Configuring AAA for Network Users
Overriding or Adding Attributes Locally with a Location Policy
Duringtheloginprocess,theAAAauthorizationprocessisstartedimmediatelyafterclientsare
authenticatedtousetheRoamAboutSwitch.Duringauthorization,MSSassignstheusertoa
VLANandappliesoptionaluserattributes,suchasasessiontimeoutvalueandoneormore
securityACLfilters.
Alocationpolicyis
asetofrulesthatenablesyoutolocallysetorchangeauthorizationattributes
forauseraftertheuserisauthorizedbyAAA,withoutmakingchangestotheAAAserver.For
example,youmightwanttoenforceVLANmembershipandsecurityACLpoliciesonaparticular
RoamAboutSwitchbasedon
aclient’sorganizationorphysicallocation,orassignaVLANto
userswhohavenoAAAassignment.Forthesesituations,youcanconfigurethelocationpolicyon
theswitch.
YoucanusealocationpolicytolocallysetorchangetheFilter‐IdandVLAN‐Nameauthorization
attributesobtainedfrom
AAA.
About the Location Policy
EachRoamAboutswitchcanhaveonelocationpolicy.Thelocationpolicyconsistsofasetofrules.
Eachrulecontainsconditions,andanactiontoperformifallconditionsintherulematch.The
locationpolicycancontainupto150rules.
Theactioncanbeoneofthefollowing:
•Denyaccess
tothenetwork
•Permitaccess,butsetorchangetheuser’sVLANassignment,inboundACL,outboundACL,
oranycombinationoftheseattributes
Theconditionscanbeoneormoreofthefollowing:
•AAA‐assignedVLAN
• Username
• DistributedAPnumber,orwiredauthenticationportthroughwhichtheuseraccessedthe
network
•SSIDnamewith
whichtheuserisassociated
ConditionswithinaruleareANDed.AllconditionsintherulemustmatchinorderforMSSto
takethespecifiedaction.Ifthelocationpolicycontainsmultiplerules,MSScomparestheuser
informationtotherulesoneatatime,intheordertherules
appearintheswitch’sconfiguration
file,beginningwiththeruleatthetopofthelist.MSScontinuescomparinguntilausermatchesall
conditionsinaruleoruntiltherearenomorerules.
Anyauthorizationattributesnotchangedbythe locationpolicyremainactive.
How the Location Policy Differs from a Security ACL
Althoughstructurallysimilar,thelocationpolicyandsecurityACLshavedifferentfunctions.The
locationpolicyonaRoamAboutSwitchcanbeusedtolocallyredirectausertoadifferentVLAN
orlocallycontrolthetraffictoandfromauser.
Incontrast,securityACLsarepacketfiltersappliedtothe
userthroughoutaMobilityDomain.
(Formoreinformation,seeChapter 1 5,ConfiguringandManagingSecurityACLs.)
YoucanusethelocationpolicytolocallyapplyasecurityACLtoauser.