Command Reference Guide

244 CHAPTER 7: AAA COMMANDS
Conditions within a rule are ANDed. All conditions in the rule must match
for MSS to take the specified action. If the location policy contains
multiple rules, MSS compares the user information to the rules one at a
time, in the order the rules appear in the switch’s configuration file,
beginning with the rule at the top of the list. MSS continues comparing
until a user matches all conditions in a rule or until there are no more
rules.
The order of rules in the location policy is important to ensure users are
properly granted or denied access. To position rules within the location
policy, use before rule-number and modify rule-number in the set
location policy command, and the clear location policy rule-number
command.
When applying security ACLs:
Use inacl inacl-name to filter traffic that enters the switch from users via
an MAP access port or wired authentication port, or from the network via
a network port.
Use outacl outacl-name to filter traffic sent from the switch to users via
an MAP access port or wired authentication port, or from the network via
a network port.
You can optionally add the suffixes .in and .out to inacl-name and
outacl-name so that they match the names of security ACLs stored in the
local WX database.
Examples — The following command denies network access to all users
at *.theirfirm.com, causing them to fail authorization:
WX4400# set location policy deny if user eq *.theirfirm.com
The following command authorizes access to the guest_1 VLAN for all
users who are not at *.wodefirm.com:
WX4400# set location policy permit vlan guest_1 if user neq
*.wodefirm.com
The following command authorizes users at *.ny.ourfirm.com to access
the bld4.tac VLAN instead, and applies the security ACL tac_24 to the
traffic they receive:
WX4400# set location policy permit vlan bld4.tac
outacl tac_24 if user eq *.ny.ourfirm.com