Users Guide

Table Of Contents
332 | Roles and Policies Dell PowerConnect W-Series ArubaOS 6.1 | User Guide
The following table describes some of the DHCP options that are useful for assigning a user role or VLAN.
The device identification features in ArubaOS can also automatically identify different client device types and
operating systems by parsing the User-Agent strings in the client’s HTTP packets. To enable this feature, select
the Device Type Classification option in the AP’s AAA profile. For details, see “Device Type Classification” on
page144.
Configuring a User-derived Role or VLAN in the WebUI
1. Navigate to the Configuration > Security > Authentication > User Rules page.
2. Click Add to add a new set of derivation rules. Enter a name for the set of rules, and click Add. The name
appears in the User Rules Summary list.
3. In the User Rules Summary list, select the name of the rule set to configure rules.
4. Click Add to add a rule. For Set Type, select Role from the drop-down menu. (You can select VLAN to create
a derivation rules for setting the VLAN assigned to a client.)
5. Configure the condition for the rule by setting the Rule Type, Condition, Value parameters and optional
description of the rule. See Table 61 for descriptions of these parameters.
6. Select the role assigned to the client when this condition is met.
7. Click Add.
8. You can configure additional rules for this rule set. When you have added rules to the set, use the up or down
arrows in the Actions column to modify the order of the rules. (The first matching rule is applied.)
9. Click Apply.
10. (Optional) If the rule uses the DHCP-Option condition, best practices is to enable the Enforce DHCP
parameter in the AP group’s AAA profile, which requires users to complete a DHCP exchange to obtain an IP
address. For details on configuring this parameter in an AAA profile, see “Configuring Authentication” on
page143.
Configure a User-derived Role or VLAN in the CLI
aaa derivation-rules user <name>
set role|vlan
condition bssid|dhcp-option|dhcp-option-77|encryption-type|essid|location|macaddr
contains|ends-with|equals|not-equals|starts-with|value-of <string>
set-value <role>
position <number>
See Table 61 for descriptions of these parameters.
DHCP Option values
DHCP Option Description Hexadecimal Equivalent
12 Host name 0C
55 Parameter Request List 37
60 Vendor Class Identifier 3C
81 Client FQDN 51