CLI Reference Guide
274 CHAPTER 7: CONFIGURING AUTHENTICATION, AUTHORIZATION, AND ACCOUNTING PARAMETERS
Configuring User
Authorization
Attributes
Authorization attributes can be assigned to users in the local database or
on remote servers. The attributes, which include access control list (ACL)
filters, VLAN membership, encryption type, session time-out period, and
other session characteristics, let you control how and when users access
the network. When a user or group is authenticated, the local database
or RADIUS server passes the authorization attributes to MSS to
characterize the user’s session.
This section describes how to configure vendor-specific attributes (VSAs)
for users or group in the WX switch’s local database. To configure
attributes an RADIUS server, see the documentation for the server.
The only required user attribute is the VLAN name, which you specify
when you configure the user or user group.
If you require this user to have administrative access to the wireless
switches, you will also need to set the service-type attribute to 6.
To configure user authorization attributes
1 Click User Attributes at the top of the wizard you are using to create or
modify attributes a user or user group. The wizard should be one of the
following:
Create User wizard
Create User Group wizard
Create MAC Address User wizard
Create MAC User group wizard
The User Attributes page appears.
2 In the attribute row you want to configure, click the Attribute Value
column.
See Table 24 for a description of user attributes and their values.
In 3WXM, the VLAN-Name attribute is defined in the VLAN Name box in
the Setup pages for User, User Group, MAC Address User, and MAC
Address User Group.
3 Type the new attribute value in lowercase characters. ACL names are
case-sensitive.
4 Repeat step 2 and step 3 for each attribute value you want to change.
5 Click Finish to save changes and close the wizard.