Users Guide

344 Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
Attribute Description
Dest-IP-Address
Dst-IP-Address and Dst-Port are the IP address and port at which
Policy Manager received the request (RADIUS, TACACS+, etc.)
Dest-Port
Protocol Request protocol: RADIUS, TACACS+, WebAuth
NAD-IP-Address IP address of the network device from which the request originated
Client-Mac-Address MAC address of the client
Client-Mac-Address-Colon, Client-Mac-
Address-Dot, Client-Mac-Address-Hyphen,
Client-Mac-Address-Nodelim
Client MAC address in different formats
Client-IP-Address IP address of the client (if known)
Connection namespace appears in the following editing contexts:
n Service rules
n Role mapping policies
l
Authentication Namespace
- The authentication namespace can be used in role mapping policies to define roles
based on what kind of authentication method was used or what the status of the authentication is. The attribute
names and possible values with descriptions are shown in the table below:
Table 220:
Authentication Namespace Attributes
Attribute
Name
Values
InnerMethod PAP
CHAP
MSCHAP
EAP-GTC
EAP-MSCHAPv2
EAP-MD5
EAP-TLS
OuterMethod PAP
CHAP
MSCHAP
EAP-MD5
EAP-TLS
EAP-TTLS
EAP-FAST
EAP-PEAP
Phase1PAC l None - No PAC was used to establish the outer tunnel in the EAP-FAST authentication method
l Tunnel - A tunnel PAC was used to establish the outer tunnel in the EAP-FAST authentication
method
l Machine - A machine PAC was used to establish the outer tunnel in the EAP-FAST
authentication method; machine PAC is used for machine authentication (See EAP-FAST in