360
C
HAPTER
7: C
ONFIGURING
A
UTHENTICATION
, A
UTHORIZATION
,
AND
A
CCOUNTING
P
ARAMETERS
Mapping User-Based ACLs
When you map a user-based ACL, you can use any defined ACL, even if
that ACL is also mapped to a port, VLAN, or virtual port.
Y
ou can set a Filter-Id authorization attribute at the RADIUS server or at
the WX switch’s local database. The Filter-Id
attribute is a security ACL
name (or two ACL names) with the direction of the packets indicated.
The security ACL mapped by Filter-Id instructs the WX switch to use its
local definition of the ACL, including the flow direction, to filter packets
for the authenticated user.
■
If you are configuring Filter-ID attributes for a user in a WX switch’s
local database, use the filter-id.in attribute to specify an inbound ACL
and use the filter-id.out attribute to specify an outbound ACL.
■
If you are configuring the attributes on a RADIUS server, MSS can
receive the Filter-ID attribute with the
Profile
value for an inbound
ACL and the
OutboundACL
for an outbound ACL. On the RADIUS
server, the value field of filter-id can specify up to two ACLs. Any of
the following are valid for MSS:
■
filter-id = “Profile=acl1”
■
filter-id = “OutboundACL=acl2”
■
filter-id = “Profile=acl1 OutboundACL=acl2”
The format in which to enter these values depends on the RADIUS
server.
The security ACLs mapped by Filter-Id instruct the WX switch to use its
local definition of the ACL, including the flow direction, to filter packets
for the authenticated user.
For more information about assigning attributes in the local WX
database, see “Configuring User Authorization Attributes” on page 310.
For more information about adding attributes to a RADIUS database, see
your RADIUS documentation.
Содержание 3CRWX120695A
Страница 14: ......
Страница 18: ...18 ABOUT THIS GUIDE...
Страница 33: ...Uninstalling 3WXM 33...
Страница 34: ...34 CHAPTER 1 INSTALLING 3WXM...
Страница 243: ...Configuring IP Services 243 2 Click New IP Alias The Create IP Alias dialog box appears...
Страница 256: ...256 CHAPTER 6 CONFIGURING WIRELESS PARAMETERS 4 To create an SSID click New SSID The Create SSID wizard appears...
Страница 267: ...Configuring a Radio Profile 267 4 Select New Radio Profile The Create Radio Profile wizard appears...
Страница 286: ...286 CHAPTER 6 CONFIGURING WIRELESS PARAMETERS 4 Click New Distributed MAP The Create Distributed MAP wizard appears...
Страница 290: ...290 CHAPTER 6 CONFIGURING WIRELESS PARAMETERS...
Страница 345: ...Configuring Mobility Profiles 345 4 Click New Mobility Profile The Create Mobility Profile wizard appears...
Страница 410: ...410 CHAPTER 9 MANAGING CERTIFICATES...
Страница 468: ...468 CHAPTER 10 MONITORING THE NETWORK...
Страница 482: ...482 CHAPTER 11 DETECTING AND COMBATTING ROGUE DEVICES...
Страница 498: ...498 CHAPTER 12 GENERATING REPORTS...
Страница 500: ...500 APPENDIX A USING 3WXM WITH HP OPENVIEW...
Страница 516: ...516 APPENDIX B CHANGING 3WXM PREFERENCES...
Страница 534: ...534 APPENDIX C 3WXM VERIFICATION RULES...
Страница 560: ...560 APPENDIX D CHANGING MONITORING SERVICE PREFERENCES...