Operation Manual

AAA Commands
AAA Commands
9 – 181
time-of-day
(network access mode
only)
Day(s) and time(s) during which
the user is permitted to log into
the network.
After authorization, the user
session can last until either the
Time-Of-Day range or the
Session-Timeout duration (if
set) expires, whichever is
shorter.
Note: Time-Of-Day is a Trapeze
vendor-specific attribute (VSA).
The vendor ID is 14525, and the
vendor type is 4.
One of the following:
never—Access is always denied.
any—Access is always allowed.
al—Access is always allowed.
One or more ranges of values that consist of one of the
following day designations (required), and a time
range in hhmm-hhmm 4-digit 24-hour format
(optional):
mo—Monday
tu—Tuesday
we—Wednesday
th—Thursday
fr—Friday
sa—Saturday
su—Sunday
wk—Any day between Monday and Friday
Separate values or a series of ranges (except time ranges)
with commas (,) or a vertical bar (|). Do not use spaces.
The maximum number of characters is 253.
For example, to allow access only on Tuesdays and
Thursdays between 10 a.m. and 4 p.m., specify the
following: time-of-day tu1000-1600,th1000-1600
time-of-day
(network access mode
only)
(cont.)
To allow access only on weekdays between 9 a.m and
5 p.m., and on Saturdays from 10 p.m. until 2 a.m.,
specify the following:
time-of-day wk0900-1700,sa2200-0200
(Also see the examples for set user attr on page 9-186.)
Note: You can use time-of-day in conjunction with
start-date, end-date, or both.
url
(network access mode
only)
URL to redirect the user after
successful WebAAA.
Web URL, in standard format. For example:
http://www.example.com
Note: You must include the http:// portion.
You can dynamically include any of the variables in the
URL string:
$u—Username
$v—VLAN
$s—SSID
$p—Service profile name
To use the literal character $ or ?, use the following:
$$
$q
user-name
name
User name to be displayed User name up to 80 characters and can be numbers and
special characters.
vlan-name
(network access mode
only)
Virtual LAN (VLAN)
assignment.
Note: VLAN-Name is a Trapeze
vendor-specific attribute (VSA).
The vendor ID is 14525, and the
vendor type is 1.
Note: On some RADIUS
servers, you might need to use
the standard RADIUS attribute
Tunnel-Pvt-Group-ID, instead
of VLAN-Name.
Name of a VLAN that you want the user to use. The
VLAN must be configured on an MX within the Mobility
Domain to which this MX belongs.
Table 9– 9. Authentication Attributes for Local Users (continued)
Attribute Description Valid Value(s)