Users Guide

Table Of Contents
b. Under Firewall Policies, click Add.
c. Select the previously-configured policy name from the Choose from Configured Policies drop-down
menu.
d. Click Done.
e. Under Firewall Policies, click Add.
f. Select control from the Choose from Configured Policies drop-down menu.
g. Click Done.
8. Click Apply.
In the CLI
To configure user roles for ALGs:
(host)(config)#ip access-list session <policy-name>
(host)(config-sess-<policy-name>) #any any <service-name> permit queue high
To map the policy name to the user role:
(host)(config)#user-role <role-name>
(host)(config-role) #session-acl <policy-name>
Replace the following strings:
l policy-name with a string that you want to identify the roles policy
l role-name with the name you want to identify the voice user role
l service-name with any of the service names from Table 206
Using the User-Derivation Rules
The user role can be derived from attributes from the client’s association with an AP. For VoIP phones, you can
configure the devices to be placed in their user role based on the SSID or the Organizational Unit Identifier
(OUI) of the client’s MAC address.
User-derivation rules are executed before the client is authenticated.
In the WebUI
To derive a role based on SSID:
1. Navigate to Configuration > Security > Authentication > User Rules.
2. Click Add to add a new set of derivation rules. Enter a name for the set of rules, and click Add. The name
appears in the User Rules Summary list.
3. In the User Rules Summary list, select the name of the rule set to configure rules.
4. Click Add to add a rule. For Set Type, select Role from the drop-down menu.
5. For Rule Type, select ESSID.
6. For Condition, select equals.
7. For Value, enter the SSID used for the phones.
8. For Roles, select the user role you previously created.
9. Click Add.
10.Click Apply.
In the CLI
To derive a role based on SSID:
(host)(config)#aaa derivation-rules user <name of rule-set>
Dell Networking W-Series ArubaOS 6.4.x | User Guide Voice and Video | 969