Administrator Guide

Table Of Contents
4. Specify the Add Enforcement Policy > Rules tab parameters as described in the following table:
Field Action/Description
Add/Edit Rule Bring up the rules editor to add/edit a rule.
Move Up/Down Reorder the rules in the enforcement policy.
Remove Rule Remove a rule.
Table 176: Add Enforcement Policy (Rules tab)
Field Description
Conditions/Enforcement
Profiles
Select conditions for this rule. For each condition, select a matching action
(enforcement profile).
NOTE: A condition in an enforcement policy rule can contain attributes from the
following namespaces: Tips:Role, Tips:Posture, and Date.
NOTE: The value field for the Tips:Role attribute can be a role defined in Policy
Manager, or a role fetched from the authorization source. (Refer to see how Enable as
Role can be turned on for a fetched attribute). Role names fetched from the
authorization source can be entered freeform in value field. To commit the rule, click
Save.
Enforcement Profiles If the rule conditions match, attributes from the selected enforcement profiles are sent
to Network Access Device. If a rule matches and there are multiple enforcement
profiles, the enforcement profile disambiguation rules apply. Refer to Configuring
Enforcement Profiles on page 345 for a list of the default profiles.
Table 177: Add Enforcement Policy (Rules Editor)
Configuring Enforcement Profiles
This section includes the following information:
l Adding an Enforcement Profile
l Modifying an Existing Enforcement Profile
You can configure W-Policy Manager enforcement profiles globally, but they must be referenced to an
enforcement policy that is associated with a service.
For information about configuring specific enforcement profiles, see:
l Agent Enforcement on page 348
l Aruba Downloadable Role Enforcement on page 350
l Aruba RADIUS Enforcement on page 360
l Cisco Downloadable ACL Enforcement on page 362
l Cisco Web Authentication Enforcement on page 364
l ClearPass Entity Update Enforcement on page 366
l CLI Based Enforcement on page 368
l Filter ID Based Enforcement on page 370
l Generic Application Enforcement on page 372
Dell Networking W-ClearPass Policy Manager 6.6 | User Guide Configuring Enforcement | 345