Users Guide

attribute format (such as string or integer) for each VSA. For more information on VSA-derived user roles, see
Configuring a VSA-Derived Role on page 452
The following table describes Dell-specific RADIUS VSAs. For the current and complete list of all RADIUS VSAs
available in the version of ArubaOS currently running on your controller, access the command-line interface
and issue the command show aaa radius attributes.
VSA
Type Value
Description
Aruba-User-Role String 1 This VSA returns the role, to be assigned to the user post
authentication. The user will be granted access based on the
role attributes defined in the role.
Aruba-User-Vlan
Integer 2
This VSA returns the VLAN to be used by the client. Range: 1–
4094.
Aruba-Priv-
Admin-User
Integer 2 If this VSA is set in the RADIUS accept message, the user can
bypass the enable prompt.
Aruba-Admin-
Role
String 4 This VSA returns the management role to be assigned to the user
post management authentication. This role can be seen using the
command show mgmt-role in the command-line interface.
Aruba-Essid-
Name
String 5 String that identifies the name of the ESSID.
Aruba-Location-
Id
String 6 String that identifies the name of the AP location.
Aruba-Port-Id
String 7 String that identifies the Port ID.
Aruba-
Template-User
String 8 String that identifies the name of a Dell user template.
Aruba-Named-
User-Vlan
String 9 This VSA returns a VLAN name for a user. This VLANname on a
controller could be mapped to user-defined name or multiple
VLAN IDs.
Aruba-AP-Group
String 10 String that identifies the name of a Dell AP Group.
Aruba-Framed-
IPv6-Address
String 11 This attribute is used for RADIUS accounting for IPv6 users.
Aruba-Device-
Type
String 12 String that identifies a Dell device on the network.
Aruba-No-
DHCP-
Fingerprint
Integer 14 This VSA prevents the controller from deriving a role and VLAN
based on DHCP finger printing.
Table 44: RADIUS VSAs
Dell Networking W-Series ArubaOS 6.4.x | User Guide Authentication Servers | 255