Users Guide

195 Dell Networking W-ClearPass Policy Manager 6.2 | User Guide
l Dell RADIUS Enforcement - RADIUS tempate that can be filled with attributes from the Dell RADIUS dictionaries
loaded into Policy Manager.
l Dell Downloadable Role Enforcement - RADIUStemplate that can be filled with role attributes to create roles that
can be assigned to users after successful authentication.
l Filter ID Based Enforcement - All RADIUS attributes for filter-id based enforcement are pre-filled in this template.
l RADIUS Based Enforcement - Generic RADIUS tempate that can be filled with any attribute from the RADIUS
vendor dictionaries loaded into Policy Manager.
l RADIUS Change of Authorization (CoA) - Enforcement profile that encapsulates CoA actions sent to the network
device. Note that the system comes pre-packaged with default Enforcement Profiles for “Disconnect (Terminate
Session) actions for the different supported vendor devices; there is no need to create profiles for these actions.
l TACACS+ Based Enforcement - TACACS+ based enforcement profile with UI customized for TACACS+ service &
command authorization.
l SNMP Based Enforcement - Generic SNMP based enforcement profile with SNMP dictionaries for VLAN steering
and Reset Connection.
l Cisco Downloadable ACL Enforcement - RADIUS based enforcement profile with UI customized for Cisco
Downloadable ACL Enforcement.
l Cisco Web Authentication Enforcement - RADIUS based enforcement profile with pre-loaded attributes for
enforcement for Cisco switch-hosted web authentication.
l Dell Guest Enforcement - Application specific enforcement profile with pre-loaded attributes for authorization of
Guest users.
l Dell W-Insight Enforcement - Application specific enforcement profile with pre-loaded attributes for authorization
of Insight users.
l Generic Application Enforcement - Application specific enforcement profile with customization attribute-value
pairs for authorization of generic applications.
l CLI Based Enforcement - Enforcement profile that encapsulates CLI commands to be issued to the network device.
The Target Device” attribute specifies the device on which the “Command attribute is executed.
l Agent Enforcement - Enforcement profile that encapsulates attributes sent to Dell W-OnGuard agent. Attributes can
be specified to bounce the client or to send a custom message to the client.
l ClearPass Entity Update Enforcement - Post-authentication enforcement profile that can be filled with attributes to
update the tag entries in endpoints and guest users.
l Session Restrictions Enforcement - Post-authentication enforcement profile that can be filled with attributes to
restrict users based on various factors such as bandwidth usage, active session count, and also terminate sessions
when the limits are reached.
Table 103:
Add Enforcement Profile page
Parameter Description
Name/
Description
Freeform label for enforcement profile.
Type Auto-filled based on the selected template: RADIUS, TACACS, SNMP, Application,
RADIUS_CoA
Action Relevant only for RADIUS type enforcement profiles. Accept, Deny or Drop the request.