Users Guide

Table Of Contents
284 | Roles and Policies Dell PowerConnect ArubaOS 5.0 | [User Guide
Creating a User Role
The following example creates the user role ‘web-guest’ and assigns the previously-configured ‘web-only’ policy to
this user role.
In the WebUI
1. Navigate to the Configuration > Security > Access Control > User Roles page.
2. Click Add to create and configure a new user role.
3. Enter web-guest for Role Name.
4. Under Firewall Policies, click Add. From Choose from Configured Policies, select the ‘web-only’ session policy
from the list. You can click Create to create and configure a new policy.
5. Click Done to add the policy to the user role.
6. You can optionally enter configuration values as described in Table 56.
7. Click Apply to apply this configuration. The role is not created until the configuration is applied.
After assigning the user role (see “User Role Assignments” on page286), you can click the Show Reference
button to see the profiles that reference this user role.
To a delete a user role in the WebUI:
1. Navigate to the Configuration > Security > Access Control > User Roles page.
Role VLAN ID
(optional)
By default, a client is assigned a VLAN on the basis of the ingress VLAN for the client to the controller. You
can override this assignment and configure the VLAN ID that is to be assigned to the user role. You
configure a VLAN by navigating to the Configuration > Network > VLANs page.
Bandwidth Contract
(optional)
You can assign a bandwidth contract to provide an upper limit to upstream or downstream bandwidth
utilized by clients in this role. You can select the Per User option to apply the bandwidth contracts on a per-
user basis instead of to all clients in the role.
For more information, see “Bandwidth Contracts” on page285.
VPN Dialer
(optional)
This assigns a VPN dialer to a user role. For details about VPN dialer, see Chapter 15, “Virtual Private
Networks” .
Select a dialer from the drop-down list and assign it to the user role. This dialer will be available for
download when a client logs in using captive portal and is assigned this role.
L2TP Pool (optional) This assigns an L2TP pool to the user role. For more details about L2TP pools, see Chapter 15, “Virtual
Private Networks” .
Select the required L2TP pool from the list to assign to the user role. The inner IP addresses of VPN tunnels
using L2TP will be assigned from this pool of IP addresses for clients in this user role.
PPTP Pool
(optional)
This assigns a PPTP pool to the user role. For more details about PPTP pools, see Chapter 15, “Virtual
Private Networks” .
Select the required PPTP pool from the list to assign to the user role. The inner IP addresses of VPN
tunnels using PPTP will be assigned from this pool of IP addresses for clients in this user role.
Captive Portal
Profile (optional)
This assigns a Captive Portal profile to this role. For more details about Captive Portal profiles, see Chapter
12, “Captive Portal” .
Max Sessions This configures a maximum number of sessions per user in this role. The default is 65535. You can
configure any value between 0-65535.
Table 56 User Role Parameters (Continued)
Field Description
Note: If there are multiple policies for this role, policies can be re-ordered by the using the up and down buttons provided for
each policy.