HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
27 Customizing the HP-UX AAA Server Using Policies
This chapter explains how you can use policies to customize the HP-UX AAA Server.
This chapter also discusses some sample policy implementations.
This chapter addresses the following topics:
“Policy Overview” (page 411)
“Defining a Policy in a Decision File” (page 412)
Action Commands” (page 413)
Attribute Specifications” (page 422)
Attribute Functions” (page 424)
“Value Types” (page 430)
Arithmetic Expressions” (page 431)
“Supported Boolean Operators” (page 432)
“Type Compatibility” (page 434)
“Invoking a Policy” (page 435)
“Invoking Policies Through Predefined Policy Hooks” (page 435)
“Modifying the FSM for Specific Customizations ” (page 441)
“Sample Policy Implementations” (page 442)
“Dynamic Access Control” (page 442)
“ DNIS Routing” (page 444)
Policy Overview
Advanced policy actions enable you to manipulate the RADIUS contents based on the
contents of the RADIUS request and reply packets, and various system contexts (for
example, a local IP Address). Policy modules are invoked using the Finite State Machine
(FSM) and can be executed at any time during processing of the RADIUS packet. When
a policy AATV is invoked, you can specify the policy definition file. The following
predefined policy files are included in the default FSM:
request-ingress.grp
reply-egress.grp
proxy-egress.grp
proxy-ingress.grp
Policy Overview 411