7-1
7
Configuring RADIUS Server Support for
Switch Services
Overview
This chapter provides information used for configuring CoS (802.1p priority),
rate-limiting, and ACL client services on a RADIUS server. For information on
configuring client authentication capability on the switch, refer to chapter 6,
“RADIUS Authentication, Authorization, and Accounting”.
Table 7-1.
RADIUS Services Supported on the Switch
RADIUS Client and Server Requirements
■
Clients can be dual-stack, IPv4-only or IPv6 only.
■
Client authentication can be through 802.1X, MAC Auth, or Web Auth.
(Clients using Web Auth must be IPv4-capable.)
■
Server must support IPv4 and have an IPv4 address.
Service
Application Standard RADIUS
Attribute
1
HP Vendor-
Specific RADIUS
Attribute (VSA)
Cos (Priority)
per-user
59
40
Ingress Rate-Limiting
per-user
—
46
Egress Rate-Limiting
per-port
2
—
48
ACLs
IPv6 and/or IPv4 ACEs
(NAS-Filter-Rule)
per-user
92
61
NAS-Rules-IPv6 (sets IP mode to
IPv4-only or IPv4 and IPv6)
per-user
—
63
1
HP recommends using the Standard RADIUS attribute if available. Where both a standard
attribute and a VSA are available, the VSA is maintained for backwards compatibility with
configurations based on earlier software releases.
2
If multiple clients are authenticated on a port where
per-port
rules are assigned by a RADIUS
server, then the most recently assigned rule is applied to the traffic of all clients authenticated
on the port.
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......