Dell PowerConnect W Clearpass 100 Software Betriebsanweisung Seite 167

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 296
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 166
Understanding Role Assignment Rules
MAC-Address Attribute
The first three octets in a MAC address are known as Organizationally Unique Identifier (OUI), and are purchased
from the Institute of Electrical and Electronics Engineers, Incorporated (IEEE) Registration Authority. This identifier
uniquely identifies a vendor, manufacturer, or other organization (referred to by the IEEE as the “assignee) globally
and effectively reserves a block of each possible type of derivative identifier (such as MAC addresses) for the
exclusive use of the assignee. OAW-IAPs use the OUI part of a MAC address to identify the device manufacturer
and assign a desired role for users who have completed 802.1X authentication and MAC authentication.
DHCP Option and DHCP Fingerprinting
The DHCP fingerprinting allows you to identify the operating system of a device by looking at the options in the
DHCP frame. Based on the operating system type, a role can be assigned to the device.
For example, to create a role assignment rule with DHCP option, select equals from the Operator drop-down list
and enter 370103060F77FC in the String text box. Since 370103060F77FC is the fingerprint for Apple iOS devices
such as iPad and iPhone, OAW-IAP assigns Apple iOS devices to the role that you choose.
Device DHCP Option DHCP Fingerprint
Apple iOS Option 55 370103060F77FC
Android Option 60 3C64686370636420342E302E3135
Blackberry Option 60 3C426C61636B4265727279
Windows 7/Vista Desktop Option 55 37010f03062c2e2f1f2179f92b
Windows XP(SP3, Home,
Professional)
Option 55 37010f03062c2e2f1f21f92b
Windows Mobile Option 60 3c4d6963726f736f66742057696e646f777320434500
Windows 7 Phone Option 55 370103060f2c2e2f
Apple Mac OSX Option 55 370103060f775ffc2c2e2f
Table 28:
Validated DHCP Fingerprint
802.1X-Authentication-Type
You can also to use client 802.1X authentication to assign a desired role for users who have completed 802.1X
authentication.
Creating Role Assignment Rules
You can configure rules for determining the role that is assigned for each authenticated client.
When creating more than one role assignment rule based on RADIUS attributes, a DHCP option, and
802.1X-authentication-type, the first matching rule in the rule list is applied.
You can create a role assignment rules by using the Instant UI or CLI.
In the Instant UI
1. In the WLAN (Network>New>New WLAN or Network>edit>Edit <WLAN-profile>) window or Wired Network
configuration (Wired>New>New Wired Network or Wired>Edit>Edit Wired Network) window, click the
AOS-W Instant 6.2.1.0-3.3| User Guide Roles and Policies | 167
Seitenansicht 166
1 2 ... 162 163 164 165 166 167 168 169 170 171 172 ... 295 296

Kommentare zu diesen Handbüchern

Keine Kommentare