
ROLE-POLICY 20 - 3
20.1.1 default-role
role-policy
When a client fails to find a matching role, the default role action is assigned to that client.
Supported in the following platforms:
• RFS7000
• RFS6000
• RFS4000
• AP71xx
• AP650
• AP6511
• AP6532
Syntax
default-role use [ip-access-list|mac-access-list]
default-role use ip-access-list [in|out] <IP-ACCESS-LIST> precedence
<1-100>
default-role use mac-access-list [in|out] <MAC-ACCESS-LIST> precedence
<1-100>
Parameters
Example
rfs7000-37FABE(config-role-policy-test)#default-role use ip-access-list in test
precedence 1
rfs7000-37FABE(config-role-policy-test)#
rfs7000-37FABE(config-device-00-15-70-37-FA-BE)#show role wireless-clients on
rfs7000-37FABE
Role: role1, precedence 1
No ROLE statistics found.
rfs7000-37FABE(config-device-00-15-70-37-FA-BE)#
use ip-access-list [in|out] <IP-
ACCESS-LIST> precedence
<1-100>
Uses an IP access-list
• in – Applies the rule to incoming packets
• out – Applies the rule to outgoing packets
The following parameters are common for the above:
• <IP-ACCESS-LIST> – Specifies the access list name
• precedence – Based on the packets received, the lower
precedence value is evaluated first
• <1-100> – Specifies a precedence value between 1 and 100
use mac-access-list [in|out]
<MAC-ACCESS-LIST>
precedence <1-100>
Uses a MAC access-list
• in – Applies the rule to the incoming packets
• out – Applies the rule to the outgoing packets
The following parameters are common for the above:
• <MAC-ACCESS-LIST> – Specifies the access-list name
• precedence <1-100> – Based on the packets received, the
lower precedence value is evaluated first
• <1-100> – Specifies the precedence value between 1 and
100
Kommentare zu diesen Handbüchern