HP-UX AAA Server A.08.00.01 Administrator's Guide
27 Customizing the HP-UX AAA Server Using Policies
This chapter explains how you can use policies to customize the HP-UX AAA Server.
This chapter also discusses some sample policy implementations.
This chapter addresses the following topics:
• “Policy Overview” (page 405)
• “Defining a Policy in a Decision File” (page 406)
— “Action Commands” (page 407)
— “Attribute Specifications” (page 415)
— “Value Types” (page 423)
— “Supported Operators” (page 424)
— “Type Compatibility” (page 425)
• “Invoking a Policy” (page 426)
— “Invoking Policies Through Predefined Policy Hooks” (page 426)
— “Modifying the FSM for Specific Customizations ” (page 432)
• “Sample Policy Implementations” (page 433)
— “Dynamic Access Control” (page 433)
— “ DNIS Routing” (page 435)
Policy Overview
Advanced policy actions enable you to manipulate the RADIUS contents based on the
contents of the RADIUS request and reply packets, and various system contexts (for
example, a local IP Address). Policy modules are invoked using the Finite State Machine
(FSM) and can be executed at any time during processing of the RADIUS packet. When
a policy AATV is invoked, you can specify the policy definition file. The following
predefined policy files are included in the default FSM:
• request-ingress.grp
• reply-egress.grp
• proxy-egress.grp
• proxy-ingress.grp
Policy Overview 405