Configure Roles

Roles are assigned to clients, and the assigned role follows the client as they roam around the network. The default non-authenticated role is assigned to a client automatically when it accesses the network. If MBA or WPA2 Enterprise w/ RADIUS is configured for the network, then the RADIUS server performing the authentication can assign the client to a different role that is not the default role.

Rules are one or more actions to take on a packet matching criteria. A role can contain a maximum of 64 rules. Any combination of rules are supported. Only the policy rules assigned to a client are applied to a client's traffic. If no rule is defined, the role's default action is taken. Allowed traffic can also be assigned a Class of Service. For more information, see Matching Policy Rules Criteria.

To define roles that the RADIUS server can assign to clients, but which are not necessarily used as the default role for a service:

  1. Select Configure > Policy > Roles from the menu.
    The Roles list displays.
  2. Select Add to create a new role. Alternatively, select a role from the list and select Configure Role.
    The Configure Role page opens.
  3. Edit the fields.
    Click to expand in new window
    Configure Role Page
    GUID-797D4B38-F928-4BD4-9BFC-CC4A313B856B-low.png
    Name Roles are usually named for a type of user, such as Student, Doctor, Guest, or Staff. If RADIUS servers are used, the role name should match the filter ID values set up on the RADIUS servers.
    Bandwidth Limit When this option is selected, a slider displays that lets you set the limit. Optionally, select GUID-9DB580B1-7468-4525-8560-86DD0C7432C7-low.png to either edit the CoS under the bandwidth limit or select a pre-defined CoS and modify it. (Using a pre-defined CoS does not require using the bandwidth slider.)
    Note

    Note

    For more information about CoS, see Configuring Class of Service.
    Default Action The default action is applied when the current packet does not match any of the role's rules.
    Allow Allows the packet to be forwarded on the network's default VLAN.
    Deny Any packet that does not match a rule in the role is dropped.
    Contain to VLAN Specifies that traffic not matching any of the role's rules will be forwarded on the VLAN specified in the VLAN IDs field.
    VLAN IDs Specify the VLAN ID. This only applies if the role's default action is Contain to VLAN.
    Note

    Note

    Including multiple VLANs in the VLAN ID field causes ExtremeWireless WiNG APs to load balance traffic across all of the listed VLANs. This is an advanced option and should only be enabled in special cases. APs use the lowest numbered VLAN in the list and do not load balance across the VLANs.
  4. (Optional) To configure a Layer 2 rule, expand the L2 section using the corresponding down arrow, expand the L2. Select a rule from the list to edit or select New to add a rule.
  5. (Optional) To configure a Layer 3/4 rule, expand the L3,L4 section using the corresponding down arrow. Select a rule from the list to edit or select New to add a rule.
  6. (Optional) To configure a Layer 7 (application) rule, expand the L7 section using the corresponding down arrow. Select a rule from the list to edit or select New to add a rule.
  7. Select Save on the Configure Role page.
For more information about roles, see Roles.