Users Guide

l Generic Application Enforcement - Application specific enforcement profile with customization attribute-value
pairs for authorization of generic applications.
l CLI Based Enforcement - Enforcement profile that encapsulates CLI commands to be issued to the network
device. The ā€œTarget Deviceā€ attribute specifies the device on which the ā€œCommandā€ attribute is executed.
l Agent Enforcement - Enforcement profile that encapsulates attributes sent to Dell OnGuard agent. Attributes
can be specified to bounce the client or to send a custom message to the client.
l ClearPass Entity Update Enforcement - Post-authentication enforcement profile that can be filled with
attributes to update the tag entries in endpoints and guest users.
l Session Restrictions Enforcement - Post-authentication enforcement profile that can be filled with attributes to
restrict users based on various factors such as bandwidth usage, active session count, and also terminate sessions
when the limits are reached.
Table 116:
Add Enforcement Profile page
Parameter Description
Name/
Description
Freeform label for enforcement profile.
Type Auto-filled based on the selected template: RADIUS, TACACS, SNMP, Application, RADIUS_CoA
Action Relevant only for RADIUS type enforcement profiles. Accept, Deny or Drop the request.
Device Group
List
Associate the profile with pre-configured Device Groups.
l Add New Device Group to add a new device group.
l Add to add a device group from this drop-down list.
l Remove, View Details, Modify to remove, view the details of, or modify the selected
enforcement profile, respectively
NOTE: This feature does not work with RADIUS CoA type Enforcement Profiles.
The remaining Enforcement Profile tabs vary in content, depending on the
Template Type
(auto-specified in the
Type field when a Template has been selected):
l "RADIUS Enforcement Profiles " on page 221
l "RADIUS CoA Enforcement Profiles" on page 223
l "SNMP Enforcement Profiles " on page 224
l "TACACS+ Enforcement Profiles " on page 224
l "Application Enforcement Profiles " on page 226
l "CLI Enforcement Profile " on page 227
l "Agent Enforcement Profiles " on page 228
l Post Authentication Enforcement Profiles
RADIUS Enforcement Profiles
RADIUS Enforcement Profiles contain name/value pairings of attributes from the RADIUS dictionaries; in this
editing context, Policy Manager displays only those attributes marked in the dictionary with the
OUT
or
INOUT
qualifier.
The following figures illustrate rules for several sample profiles:
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 221