Applying Role Policies to Users

You must be aware of some limitations in applying roles to a user.

Specifically, user role policies are only supported in proxy-mode AAA WLANs. Also, you configure the user-attribute-to-role mapping in AAA profiles. Also, there are some components that will not work in 3.5, even though the GUI would lead us to believe they do. Precedence policies are configurable at the WLAN level, but have an impact on the way that roles are assigned. Finally, we should talk about the difference between assigning UEs to roles via RADIUS and using RADIUS attributes to apply some specific policy, like rate limit, VLAN, or ACL. RADIUS attribute will always take precedence over the role assignment.