7-9
Configuring RADIUS Server Support for Switch Services
RADIUS Server Configuration for CoS (802.1p Priority) and Rate-Limiting
N o t e s
Mixing CLI-configured and RADIUS-assigned rate-limiting on the same port
can produce unexpected results. Refer to “Per-Port Bandwidth Override” on
page 7-6.
Where multiple clients are currently authenticated on a given port where
outbound (egress) rate-limiting values have been assigned by a RADIUS
server, the port operates with the outbound rate-limit assigned by RADIUS for
the most recently authenticated client. Any earlier outbound rate-limit values
assigned on the same port for other authenticated client sessions that are still
active are superseded by the most recent RADIUS-assigned value. For exam-
ple, if client “X” is authenticated with an outbound rate-limit of 750 kbps, and
client “Y” later becomes authenticated with an outbound rate-limit of 500 kbps
while the session for client “X” is still active, then the port operates with an
outbound rate-limit of 500 kbps for both clients.
Figure 7-1. Example Illustrating Results of Client Authentication on Port 4
Assignment Method on Port 10
802.1p
Inbound Rate-Limit
Outbound Rate-Limit
Statically Configured Values
7
100,000 kbs
100,000 kbs*
RADIUS-assigned when client
“X” authenticates
3
10,000 kbs
50,000 kbs*
*Combined rate-limit output for all clients active on the port.
HP Switch(eth-10)# show port-access web-based clients 4 detail
Port Access Web-Based Client Status Detailed
Client Base Details :
Port : 4
Session Status : authenticated Session Time(sec): 125
Username : client-X MAC Address : 0017a4-e6d787
IP : n/a
Access Policy Details :
COS Map : 33333333 In Limit Kbps : 10000
Untagged VLAN : 10 Out Limit Kbps : 50000
Tagged VLANs : 20
RADIUS-ACL List : No Radius ACL List
I
ndicates there is an authenticated
client session running on port 10.
Shows the values assigned to the client’s traffic for inbound CoS
(802.1p priority) and client’s maximum inbound traffic volume.
Shows the RADIUS-assigned value on the
port for maximum outbound traffic volume.
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......