Users Guide

Figure 354: Add Enforcement Policy > Rules Editor
4. Specify the Add Enforcement Policy > Rules tab parameters as described in the following table:
Field Action/Description
Add Rule Click this button to bring up the Rules Editor.
Move
Up/Down
To reorder the rules in the enforcement policy, select an enforcement policy rule, then click Move
Up or Move Down.
Remove
Rule
To delete a rule, select the rule, then click Remove Rule.
Table 188: Add Enforcement Policy: Rules Editor
Field Description
Conditions/Enforcement
Profiles
Select conditions for this rule. For each condition, select a matching action
(enforcement profile).
NOTE: A condition in an enforcement policy rule can contain attributes from the
following namespaces: Tips:Role, Tips:Posture, and Date.
NOTE: The value field for the Tips:Role attribute can be a role defined in Policy
Manager, or a role fetched from the authorization source.
You can enter role names fetched from the authorization source free-form in the Value
field. To commit the rule, click Save.
Enforcement Profiles If the rule conditions match, attributes from the selected enforcement profiles are sent
to the Network Access Device. If a rule matches and there are multiple enforcement
profiles, the enforcement profile disambiguation rules apply. Refer to Configuring
Enforcement Profile on page 373 for a list of the default profiles.
Table 189: Add Enforcement Policy: Rules Editor
Configuring Enforcement Profile
Dell Networking W-ClearPass Policy Manager 6.6 | User Guide Configuring Enforcement Policies and Profiles | 373