Users Guide

Figure 126: AD/LDAP Configure Filter - Attributes Tab
Parameter Description
Enter
values for
parameters
Policy Manager parses the filter query (created in the Filter tab and shown at the top of
the Attributes tab) and prompts to enter the values for all dynamic session
parameters in the query. For example, if you have %{Authentication:Username} in
the filter query, you are prompted to enter the value for it. You can enter wildcard
character (*) here to match all entries.
NOTE: If there are thousands of entries in the directory, entering the wildcard
character (*) can take a while to fetch all matching entries.
Execute After entering the values for all dynamic parameters, click Execute to execute the filter
query. You can see all entries that match the filter query. Click on one of the entries
(nodes) to view the list of attributes for that node. You can now click on the attribute
names that you want to use as role mapping attributes.
Name Specify the name of the attribute.
Alias Name
Specify the alternative name for the attribute. By default, this is the same as the
attribute name.
Enable As
Click this to enable this attribute value to be used directly as a role in an Enforcement
Policy. This bypasses the step of assigning a role in Policy Manager through a Role
Mapping Policy.
Table 87:
AD/LDAP Configure Filter Page - Attributes tab Paramters
Dell Networking W-ClearPass Policy Manager 6.4 | User Guide Authentication and Authorization | 167