7-22
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
Configuring an ACL in a RADIUS Server
This section provides general guidelines for configuring a RADIUS server to
specify RADIUS-assigned ACLs. Also included is an example configuration for
a FreeRADIUS server application. However, to configure support for these
services on a specific RADIUS server application, please refer to the docu-
mentation provided with the application.
N o t e
This application requires a RADIUS server having an IPv4 address. Clients can
be dual-stack, IPv4-only or IPv6-only.
A RADIUS-assigned ACL configuration in a RADIUS server includes the
following elements:
■
Nas-Filter-Rule attributes: standard and vendor-specific
■
ACL configuration, entered in the server, and associated with specific
username/password or MAC address criteria, and comprised of ACEs
entered in the server
A RADIUS-assigned ACL includes:
■
one or more explicit “permit” and/or “deny” ACEs
■
an implicit
deny in ip from any to any
ACE automatically applied after
the last operator-created ACE
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......