user-role
user-role
access-list {eth|mac|session}
bw-contract
app
appcategory
exclude {app|appcategory}
web-cc-category
web-cc-reputation {high-risk|low-risk|moderate-risk|suspicious|trustworthy}
captive-portal {
dialer
dpi
max-sessions
no ...
openflow-enable
pool {l2tp|pptp
qos-profile
reauthentication-interval [
registration-role
robust-age-out
sso
stateful-kerberos
stateful-ntlm
via
vlan {VLAN ID|VLAN name}
web-cc disable
wispr
Description
This command configures a user role.
Every client in a user-centric network is associated with a user role. All wireless clients start in an initial role. From the initial role, clients can be placed into other user roles as they pass authentication.
Parameter |
Description |
Role name |
|
access-list |
Type of ACL to be applied: eth:Ethertype ACL, configured with the mac:MAC ACL, configured with the session:Session ACL, configured with the |
Name of the configured ACL. |
|
ap-group |
(Optional) AP group to which this ACL applies. |
position |
(Optional) Position of this ACL relative to other ACLs that you can configure for the user role. 1 is the top. Default:(last) |
bandwidth- contract |
Name of a bandwidth contract or rate limiting policy configured with the |
app |
Name of the application bandwidth contract configured for the user role. The bandwidth contract must be applied to either downstream or upstream traffic. For a complete list of supported applications, issue the command |
appcategory |
Name of the application category bandwidth contract configured for the user role. The bandwidth contract must be applied to either downstream or upstream traffic. For a complete list of supported applications, issue the command |
web-cc-category|web-cc-reputation |
Apply a bandwidth conract to the specified web content category or reputation level. Bandwidth contracts can be applied to user-defined web content categories created using the web-cc command. The five web content reputation levels are predefined inArubaOS. bandwidth contracts applied to a web content category or reputation will not be enforced unless web content classification is enabled using the Range:Available reputation categories are: high-risk low-risk moderate-risk suspicious trustworthy |
exclude |
Excludes an application or application category from being configured as a bandwidth contract. |
downstream |
Applies the bandwidth contract to traffic from thecontrollerto the client. |
per-user |
Specifies that bandwidth contract is assigned on a per-user basis instead of a per-role basis. For example, if two users are active on the network and both are part of the same role with a 500 Kbps bandwidth contract, then each user is able to use up to 500 Kbps. Default:(per role) |
upstream |
Applies the bandwidth contract to traffic from the client to thecontroller. |
captive-portal |
Name of the captive portal profile configured with the |
check-for-accounting |
如果禁用,半径/ng is done for an authenticated users irrespective of the captive-portal profile in the role of an authenticated user. If enabled, accounting is not done as long as the user's role has a captive portal profile on it. Accounting will start when Auth/XML-Add/CoA changes the role of an authenticated user to a role which doesn't have captive portal profile. Default:Enabled |
dialer |
If VPN is used as an access method, name of the VPN dialer configured with the |
dpi |
Role specific DPI configuration. |
disable |
禁用特定DPI配置作用。 |
max-sessions |
Maximum number of datapath sessions per user in this role. Range:0-65535 Default:65535 |
no |
Negates any configured parameter. |
openflow-enable |
Enables SDN for the user role. Default:Enabled |
pool |
If VPN is used as an access method, specifies the IP address pool from which the user’s IP address is assigned: l2tp: When a user negotiates an L2TP or IPsec session, specifies an address pool configured with the pptp: When a user negotiates a PPTP session, specifies an address pool configured with the via-dhcp:Defines an external DHCP server address instead of internal L2TP pool and themanaged devicegets the IP address from an external DHCP server. L2TP pool and DHCP pool configuration in a role are mutually exclusive. |
Name of the L2TP or PPTP |
|
qos-profile |
Applies a QOS profile to the user role. |
reauthentication-interval |
Interval, in minutes or seconds, after which the client is required to reauthenticate. Range:0-4096 in minutes 0-245760 in seconds Default:0(disabled) |
registration-role |
If enabled, a user is forced to do MAC-based authentication every time the user connects to the network. Default:disabled |
robust-age-out |
Apply Robust Age-out mechanism on wired passive clients. Disabled. This feature impacts system load and performance. Enable this mechanism for a limited number of clients only. |
sso |
Applies an SSO profile to the user role. |
statefule-kerberos |
Applies a stateful Kerberos profile to the user role. |
stateful-ntlm |
Apply stateful NTLM authentication to the specified user role |
via |
Applies a VIA connection profile to the user role. |
vlan |
Identifies the VLAN ID or VLAN name to which the user role is mapped. This parameters works only when using Layer-2 authentication such as 802.1X or MAC address, ESSID, or encryption type role mapping because these authentications occur before an IP address is assigned. If a user authenticates using a Layer-3 mechanism such as VPN or captive portal this parameter has no effect. VLAN IDs and VLAN names cannot be listed together. |
voip-profile |
Applies a VOIP profile to the user role. |
web-cc disable |
Disable web content classification for this user role. User role bandwidth contracts associated with web content classification categories and reputation types will not enforced unless web content classification is enabled using the |
wispr |
Apply WISPr authentication to the specified user role. |
Example
The following command configures a user role:
(host)[md](config) #user-role new-user
拨号器default-dialer
pool pptp-pool-1
Command History
Release |
Modification |
ArubaOS8.8.0.0 |
Added a new sub-parameter, Added a new parameter, |
ArubaOS8.0.0.0 |
Command introduced. |
Command Information
Platforms |
License |
Command Mode |
All platforms |
Requires the PEFNG license. |
Config mode onMobility Conductor. |