Specifications
set mac-user attr
Chapter 9
AAA Commands
225
service-type Type of access the user
is requesting.
One of the following numbers:
• 2—Framed; for network user access
• 6—Administrative; for administrative
access to the UNIVERGE WL
Controller, with authorization to access
the enabled (configuration) mode. The
user must enter the enable command and
the correct enable password to access the
enabled mode.
• 7—NAS-Prompt; for administrative
access to the nonenabled mode only. In
this mode, the user can still enter the
enable command and the correct enable
password to access the enabled mode.
For administrative sessions, the UNIVERGE
WL Controller always sends 6
(Administrative).
The RADIUS server can reply with one of
the values listed above.
If the service-type is not set on the RADIUS
server, administrative users receive
NAS-Prompt access, and network users
receive Framed access.
session-timeout
(network access
mode only)
Maximum number of
seconds for the user’s
session.
Number between 0 and 2,147,483,647
seconds (approximately 68.1 years).
Note. If the global reauthentication timeout
(set by the set dot1x reauth-period
command) is shorter than the
session-timeout, UNIVERGE WL Control
System uses the global timeout instead.
ssid
(network access
mode only)
SSID the user is
allowed to access after
authentication.
Name of the SSID you want the user to use.
The SSID must be configured in a service
profile, and the service profile must be used
by a radio profile assigned in the Mobility
Domain.
Table 25. Authentication Attributes for Local Users
Attribute Description Valid Value(s)