3com WX2200 3CRWX220095A User Manual

Page of 728
492
C
HAPTER
 21: C
ONFIGURING
 AAA 
FOR
 N
ETWORK
 U
SERS
Assigning Attributes
to Users and Groups
You can assign authorization attributes to individual users or groups of 
users. Use any of the following commands to assign an attribute to a user 
or group in the local WX database and specify its value:
set user username attr attribute-name value
set usergroup group-name attr attribute-name value
set mac-user mac-addr attr attribute-name value
set mac-usergroup group-name attr attribute-name value
If attributes are configured for a user and also for the group the user is in, 
the attributes assigned to the individual user take precedence for that 
user. For example, if the start-date attribute configured for a user is 
sooner than the start-date configured for the user group the user is in, 
the user’s network access can begin as soon as the user start-date. The 
user does not need to wait for the user group’s start date.
url
(network access 
mode only)
URL to which the user 
is redirected after 
successful WebAAA. 
Web URL, in standard format. For 
example:
http://www.example.com
Note: You must include the http:// 
portion.
You can dynamically include any of 
the variables in the URL string:
„
$u—Username
„
$v—VLAN
„
$s—SSID
„
$p—Service profile name
To use the literal character $ or ?, use 
the following:
„
$$
„
$q
vlan-name
(network access 
mode only)
Virtual LAN (VLAN) 
assignment.
Note: On some 
RADIUS servers, you 
might need to use the 
standard RADIUS 
attribute 
Tunnel-Pvt-Group-ID, 
instead of VLAN-Name.
Name of a VLAN that you want the 
user to use. The VLAN must be 
configured on a WX switch within the 
Mobility Domain to which this WX 
switch belongs.
Table 43   Authentication Attributes for Local Users (continued)
Attribute
Description
Valid Value(s)