Concept Guide

Parameter Description
Match-Op This is the match method by which the string in Match-Str is matched with the
attribute value returned by the authentication server.
l contains The rule is applied if and only if the attribute value contains the
string in parameter Operand.
l starts-with The rule is applied if and only if the attribute value returned
starts with the string in parameter Operand.
l ends-with The rule is applied if and only if the attribute value returned
ends with the string in parameter Operand.
l equals The rule is applied if and only if the attribute value returned
equals the string in parameter Operand.
l not-equals The rule is applied if and only if the attribute value returned
is not equal to the string in parameter Operand.
l value-of This is a special condition. What this implies is that the role or
VLAN is set to the value of the attribute returned. For this to be successful,
the role and the VLAN ID returned as the value of the attribute selected
must be already configured on the controller when the rule is applied
Match-Str This is the string to which the value of the returned attribute is matched.
Priority The priority in which role or VLAN derivation rules are applied. Rules at the
top of the list are applied before rules at the bottom.
Attribute For role or VLAN derivation rules, this is the attribute returned by the
authentication server that is examined for Operation and Operand match.
Operation For role or VLAN derivation rules, this is the match method by which the string
in Operand is matched with the attribute value returned by the
authentication
server.
l contains The rule is applied if and only if the attribute value contains the
string in parameter Operand.
l starts-with The rule is applied if and only if the attribute value returned
starts with the string in parameter Operand.
l ends-with The rule is applied if and only if the attribute value returned
ends with the string in parameter Operand.
l equals The rule is applied if and only if the attribute value returned
equals the string in parameter Operand.
l not-equals The rule is applied if and only if the attribute value returned
is not equal to the string in parameter Operand.
l value-of This is a special condition. What this implies is that the role or
VLAN is set to the value of the attribute returned. For this to be successful,
the role and the VLAN ID returned as the value of the attribute selected
must be already configured on the controller when the rule is applied.
Operand For role or VLAN derivation rules, this is the string to which the value of the
returned attribute is matched.
Dell Networking W-Series ArubaOS 6.5.x | Reference Guide show aaa server-group | 865