User's Manual
g. To add this rule to the policy, click Add.
h. Repeat the steps to configure additional rules.
i. Click Done to return to the User Roles tab. The WebUI returns to the User Roles tab.
4. Click Apply to apply the configuration changes.
5. Refer to Roles and Policies on page 364, for directions on how to apply a policy to a user role.
In the CLI
Use these commands to define the redirection filter for sending traffic to the ESI server and apply the firewall
policy to a user role.
ip access-listsessionpolicy
anyanyanyredirectesi-groupgroupdirectionbothblacklist
//For any incoming traffic, going to any destination,
//redirect the traffic to servers in the specified ESI group.
anyanyanypermit
//For everything else, allow the traffic to flow normally.
user-rolerole
access-list{eth|mac|session}
bandwidth-contractname
captive-portalname
dialername
pool {l2tp|pptp}
reauthentication-intervalminutes
session-aclname
vlanvlan_id
For example:
ip access-listsessionfortinet
anyanysvc-httpredirectesi-groupfortinetdirectionbothblacklist
anyanyanypermit
user-roleguest
access-listsessionfortinet
ESI Syslog Parser Domains and Rules
To configure the ESI syslog parser, navigate to the Configuration > Advanced Services > External Services
view on the WebUI.The following sections describe how to manage syslog parser domains using the WebUI and
CLI.
Managing Syslog Parser Domains in the WebUI
Click on the SyslogParserDomains tab to display the SyslogParser Domains view.
This view lists all the domains by domain name and server IP address, and includes a list of peer controllers
(when peer controllers have been configured—as described in Understanding the ESI Syslog Parser on page
994).
Adding a new syslog parser domain
To add a new syslog parser domain:
1. Click Add in the SyslogParser Domains section. The system displays the add domain view.
2. In the Domain Name text box, type the name of the domain to be added.
3. In the Server IP Address text box, type a valid IP address.
Dell Networking W-Series ArubaOS 6.4.x | User Guide External Services Interface | 1000