User Guide

Table Of Contents
Configuring AAA for Network Users 447
Nortel WLAN Security Switch 2300 Series Configuration Guide
filter-id
(network access
mode only)
Security access control list
(ACL), to permit or deny
traffic received (input) or sent
(output) by the WSS switch.
(For more information about
security ACLs, see
“Configuring and Managing
Security ACLs,” on page 351.)
Name of an existing security ACL, up to
253 alphanumeric characters, with no tabs or spaces.
•Use acl-name.in to filter traffic that enters the
switch from users through an AP access point or
wired authentication port, or from the network
through a network port.
•Use acl-name.out to filter traffic sent from the
switch to users through an AP access point or
wired authentication port, or from the network
through a network port.
Note: If the Filter-Id value returned through the
authentication and authorization process does not
match the name of a committed security ACL in the
WSS, the user fails authorization and is unable to
authenticate.
idle-timeout This option is not implemented in the current WSS Software version.
mobility-profile
(network access
mode only)
Mobility Profile attribute for
the user. (For more
information, see “Configuring
a Mobility Profile” on
page 468.)
Name of an existing Mobility Profile, which can be
up to 32 alphanumeric characters, with no tabs or
spaces.
Note: If the Mobility Profile feature is enabled, and
a user is assigned the name of a Mobility Profile that
does not exist on the WSS switch, the user is denied
access.
service-type Type of access the user is
requesting.
One of the following numbers:
2—Framed; for network user access
6—Administrative; for administrative access to
the WSS switch, with authorization to access the
enabled (configuration) mode. The user must
enter the enable command and the correct
enable password to access the enabled mode.
7—NAS-Prompt; for administrative access to
the nonenabled mode only. In this mode, the
user can still enter the enable command and the
correct enable password to access the enabled
mode.
For administrative sessions, the WSS switch always
sends 6 (Administrative).
The RADIUS server can reply with one of the values
listed above.
If the service-type is not set on the RADIUS server,
administrative users receive NAS-Prompt access,
and network users receive Framed access.
session-timeout
(network access
mode only)
Maximum number of seconds
for the user’s session.
Number between 0 and 4,294,967,296 seconds
(approximately 136.2 years).
Table 32: Authentication Attributes for Local Users (continued)
Attribute Description Valid Values