Administrator Guide

Table Of Contents
(host)(config) #aaa profile <profile>
To configure the default user role for other authentication methods:
(host)(config) #aaa authentication captive-portal|stateful-dot1x|stateful-ntlm|vpn
Configuring a Server-Derived Role
If the client is authenticated through an authentication server, the user role for the client can be based on one
or more attributes returned by the server during authentication. You configure the user role to be derived by
specifying condition rules; when a condition is met, the specified user role is assigned to the client. You can
specify more than one condition rule; the order of rules is important as the first matching condition is applied.
You can also define server rules based on client attributes such as ESSID, BSSID, or MAC address, even though
these attributes are not returned by the server.
For information about configuring a server-derived role, see Configuring Server-Derivation Rules on page 270.
Configuring a VSA-Derived Role
Many Network Address Server (NAS) vendors, including Dell, use VSAs to provide features not supported in
standard RADIUS attributes. For Dell systems, VSAs can be employed to provide the user role and VLAN for
RADIUS-authenticated clients, however the VSAs must be present on your RADIUS server. This involves
defining the vendor (Dell) and/or the vendor-specific code (14823), vendor-assigned attribute number,
attribute format (such as string or integer), and attribute value in the RADIUS dictionary file. VSAs supported
on controllers conform to the format recommended in RFC 2865, Remote Authentication Dial In User Service
(RADIUS)”.
For more information on Dell VSAs, see RADIUS Server VSAs on page 254. Dictionary files that contain Dell
VSAs are available on the Dell support website for various RADIUS servers. Log into the Dell support website to
download a dictionary file from the Tools folder.
Understanding Global Firewall Parameters
Table 85 describes optional firewall parameters you can set on the controller for IPv4 traffic. To set these
options in the WebUI, navigate to the Configuration > Advanced Services > Stateful Firewall > Global
Setting page and select or enter values in the IPv4 column. To set these options in the CLI, use the firewall
configuration commands.
See IPv6 Support on page 198 for information about configuring firewall parameters for IPv6 traffic.
Dell Networking W-Series ArubaOS 6.4.x | User Guide Roles and Policies | 452