HP-UX AAA Server A.07.01 Administrator's Guide

25 Customizing the HP-UX AAA Server Using Policies
This chapter explains how you can use policies to customize the HP-UX AAA Server.
This chapter also discusses some sample policy implementations.
This chapter addresses the following topics:
“Policy Overview” (page 283)
“Defining a Policy in a Decision File” (page 284)
Action Commands” (page 285)
Attribute Specifications” (page 293)
“Value Types” (page 301)
“Supported Operators” (page 302)
“Type Compatibility” (page 303)
“Invoking a Policy” (page 304)
“Invoking Policies Through Predefined Policy Hooks” (page 304)
“Modifying the FSM for Specific Customizations ” (page 310)
“Sample Policy Implementations” (page 311)
“Dynamic Access Control” (page 311)
“ DNIS Routing” (page 313)
Policy Overview
Advanced policy actions enable you to manipulate the RADIUS contents based on the
contents of the RADIUS request and reply packets, and various system contexts (for
example, a local IP Address). Policy modules are invoked using the Finite State Machine
(FSM) and can be executed at any time during processing of the RADIUS packet. When
a policy AATV is invoked, you can specify the policy definition file. The following
predefined policy files are included in the default FSM:
request-ingress.grp
reply-egress.grp
proxy-egress.grp
proxy-ingress.grp
Policy Overview 283