Creating a Policy to Assign to eDPSK Pools (Optional)

Before you create a DPSK pool for a property, you can configure policies that can be applied to eDPSK pools. Policies allow for mapping incoming successful RADIUS authentication requests to a set of RADIUS response attributes based on dynamic conditions of the request.
Note: When you create a DPSK pool, you can set the default behavior of whether to accept or reject a user who does not match the acceptance criteria of any policies. If you choose to use the “Accept” setting, a user is always accepted, and you do not need to configure a policy. However, if you use "Reject” as the default policy behavior, you need to configure at least one policy that is a match for each VNI (VXLAN) in the Network Segmentation group.

Each policy has an associated RADIUS attribute group which defines the RADIUS response attributes (such as filter ID, and class). Each authentication is matched against an assigned list of candidate policies in sequential order. Criteria of a policy can include dynamic conditions such as a user's physical location, username, or the time of day.

Note: "VLAN ID" is not applicable to network segmentation. Instead, a VXLAN is assigned to a unit that is part of the network segment. This VLXAN is the virtual network identifier (VNI); for an example refer to Property Details Example After Adding Two Units.

The following procedure guides you first through creating RADIUS attribute groups for your policies, then creating the policies themselves. You must create at least one RADIUS attribute group before you can configure a policy because a policy needs to have at least one RADIUS attribute group available for selection.

  1. In the Cloudpath UI, go to Configuration > Policies.
  2. Select the RADIUS Attribute Groups tab, then click the Add RADIUS Attribute Group button.
  3. In the ensuing Create Radius Attribute Group screen, enter the information to create the group, then click Save.
    Note: You can configure as many RADIUS Attribute groups as you want. One RADIUS Attribute group will later be assigned to each policy you create.
    An example screen is shown below. For detailed steps, refer to the "Configuring Policies" section of the Cloudpath Enrollment System External Dynamic Pre-Shared Key (eDPSK) Configuration Guide.

    Create RADIUS Attribute Screen

  4. Configure your policies:
    1. In the Configuration > Policies area of the UI, select the Policies tab, then click Add Policies.
    2. In the ensuing Create Policy screen, enter the information to create the policy, then click Save.
      Note: You can configure as many policies as you want.
      An example screen follows. For detailed steps, refer to the "Configuring Policies" section of the Cloudpath Enrollment System External Dynamic Pre-Shared Key (eDPSK) Configuration Guide.

      Create Policy Screen

The following illustration shows the Policies tab after one policy has been added. The information shown in the table represents the policy configuration shown in the example in the Create Policy Screen. The attribute group name and its attributes come from the attribute group name selected in the Create Policy Screen drop-down list. (The "Certificate Reply Username" applies only to certificate-based authentications, and is therefore described in the Cloudpath documentation of certificate templates.) The RADIUS attribute information shown below comes from the example in the Create RADIUS Attribute Screen.

Policies Table Example After One Policy Is Configured