Reference Guide

Table Of Contents
Dell PowerConnect W-Series ArubaOS 6.1 CLI | Reference Guide user-role | 1271
Syntax
Parameter Description Range Default
<name>
Name of the user role.
access-list
Type of access control list (ACL) to be applied:
eth: Ethertype ACL, configured with the ip access-list eth command.
mac: MAC ACL, configured with the ip access-list mac command.
session: Session ACL, configured with the ip access-list session command.
——
<acl>
Name of the configured ACL.
ap-group
(Optional) AP group to which this ACL applies.
position
(Optional) Position of this ACL relative to other ACLs that you can configure
for the user role. 1 is the top.
(last)
bandwidth-con
tract
Name of a bandwidth contract or rate limiting policy configured with the aaa
bandwidth-contract command. The bandwidth contract must be applied to
either downstream or upstream traffic.
——
downstream
Applies the bandwidth contract to traffic from the controller to the client.
per-user
Specifies that bandwidth contract is assigned on a per-user basis instead of
a per-role basis. For example, if two users are active on the network and both
are part of the same role with a 500 Kbps bandwidth contract, then each user
is able to use up to 500 Kbps.
(per role)
upstream
Applies the bandwidth contract to traffic from the client to the controller.
captive-portal
Name of the captive portal profile configured with the aaa authentication
captive-portal command.
——
dialer
If VPN is used as an access method, name of the VPN dialer configured with
the vpn-dialer command. The user can login using captive portal and
download the dialer. The dialer is a Windows application that configures the
VPN client.
——
max-sessions
Maximum number of datapath sessions per user in this role. 0-65535 65535
no
Negates any configured parameter.
pool
If VPN is used as an access method, specifies the IP address pool from
which the user’s IP address is assigned:
l2tp: When a user negotiates a Layer-2 Tunneling Protocol (L2TP)/ IPsec
session, specifies an address pool configured with the ip local pool
command.
pptp: When a user negotiates a Point-to-Point Tunneling Protocol (PPTP)
session, specifies an address pool configured with the pptp ip local pool
command.
——
<name>
Name of the L2TP or PPTP pool to be applied.
reauthentica
tion-interval
Interval, in minutes, after which the client is required to reauthenticate. 0-4096, 0
to disable
0
(disabled)
session-acl
<string>
Session ACL configured with the ip access-list session command. You can
specify both IPv4 and IPv6 ACLs.
——
ap-group
(Optional) AP group to which this ACL applies.
position
(Optional) Position of this ACL relative to other ACLs that you can configure
for the user role. 1 is the top.
(last)
stateful-ntlm Apply stateful NTLM authentication to the specified user role