Security ACL Configuration Scenario
411
4
To map
acl-99
to port 6 to filter incoming packets, type the following
command:
WX1200#
set security acl map acl-99 port 6 in
mapping configuration accepted
Because every security ACL includes an implicit rule denying all traffic that
is not permitted, port 6 now accepts packets only from 192.168.1.1, and
denies all other packets.
5
To map
acl-99
to user Natasha’s sessions when you are using the local WX
database for authentication, configure Natasha in the database with the
Filter-Id attribute. Type the following commands:
WX1200#
set authentication dot1x Natasha local
success: change accepted.
WX1200#
set user natasha attr filter-id acl-99.in
success: change accepted.
6
Alternatively, you can map
acl-99
to Natasha’s sessions when you are
using a remote RADIUS server for authentication. To configure Natasha
for pass-through authentication to the RADIUS server
shorebirds
, type the
following command:
WX1200#
set authentication dot1x Natasha pass-through
shorebirds
success: change accepted.
You must then map the security ACL to Natasha’s session in RADIUS. For
instructions, see the documentation for your RADIUS server.
7
To save your configuration, type the following command:
WX1200#
save config
success: configuration saved.
Summary of Contents for 3CRWX120695A
Page 138: ...138 CHAPTER 6 CONFIGURING AND MANAGING IP INTERFACES AND SERVICES ...
Page 272: ...272 CHAPTER 11 CONFIGURING RF LOAD BALANCING FOR MAPS ...
Page 310: ...310 CHAPTER 13 CONFIGURING USER ENCRYPTION ...
Page 322: ...322 CHAPTER 14 CONFIGURING RF AUTO TUNING ...
Page 350: ...350 CHAPTER 16 CONFIGURING QUALITY OF SERVICE ...
Page 368: ...368 CHAPTER 17 CONFIGURING AND MANAGING SPANNING TREE PROTOCOL ...
Page 412: ...412 CHAPTER 19 CONFIGURING AND MANAGING SECURITY ACLS ...
Page 518: ...518 CHAPTER 21 CONFIGURING AAA FOR NETWORK USERS ...
Page 530: ...530 CHAPTER 22 CONFIGURING COMMUNICATION WITH RADIUS ...
Page 542: ...542 CHAPTER 23 MANAGING 802 1X ON THE WX SWITCH ...
Page 598: ...598 CHAPTER 26 ROGUE DETECTION AND COUNTERMEASURES ...
Page 706: ...706 GLOSSARY ...