PowerConnect B-Series FCX Configuration Guide
1285
53-1002266-01
Configuring multi-device port authentication
36
•
The dynamic ACL must be an extended ACL. Standard ACLs are not supported.
•
Multi-device port authentication and 802.1x can be used together on the same port. However,
Dell does not recommend the use of multi-device port authentication and 802.1X with dynamic
ACLs together on the same port. If a single supplicant requires both 802.1x and multi-device
port authentication, and if both 802.1x and multi-device port authentication try to install
different dynamic ACLs for the same supplicant, the supplicant will fail authentication.
•
Dynamically assigned IP ACLs are subject to the same configuration restrictions as
non-dynamically assigned IP ACLs. One caveat is that ports with VE interfaces cannot have
assigned user-defined ACLs. For example, a user-defined ACL bound to a VE or a port on a VE
is not allowed. There are no restrictions on ports that do not have VE interfaces.
•
Dynamic ACL filters are supported only for the inbound direction. Dynamic outbound ACL filters
are not supported.
•
Dynamic ACL assignment with multi-device port authentication is not supported in conjunction
with any of the following features:
•
IP source guard
•
Rate limiting
•
Protection against ICMP or TCP Denial-of-Service (DoS) attacks
•
Policy-based routing
•
802.1X dynamic filter
Configuring the RADIUS server to support dynamic IP ACLs
When a port is authenticated using multi-device port authentication, an IP ACL filter that exists in
the running-config file on the Dell PowerConnect device can be dynamically applied to the port. To
do this, you configure the Filter-ID (type 11) attribute on the RADIUS server. The Filter-ID attribute
specifies the name or number of the Dell IP ACL.
The following is the syntax for configuring the Filter-ID attribute on the RADIUS server to refer to a
Dell IP ACL.
The following table lists examples of values you can assign to the Filter-ID attribute on the RADIUS
server to refer to IP ACLs configured on a Dell PowerConnect device.
Value
Description
ip.
<number>
.in
1
1.
The ACL must be an extended ACL. Standard ACLs are not supported.
Applies the specified numbered ACL to the authenticated port in the inbound direction.
ip.
<name>
.in
1
,
2
2.
The
<name>
in the Filter ID attribute is case-sensitive
Applies the specified named ACL to the authenticated port in the inbound direction.
Possible values for the filter ID attribute on the
RADIUS server
ACLs configured on the Dell PowerConnect device
ip.102.in
access-list 102 permit ip 36.0.0.0 0.255.255.255 any
ip.fdry_filter.in
ip access-list standard fdry_filter
permit host 36.48.0.3
Содержание PowerConnect B-FCXs
Страница 1: ...53 1002266 01 18 March 2011 PowerConnect B Series FCX Configuration Guide ...
Страница 136: ...94 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Viewing information about software licenses 4 ...
Страница 228: ...186 PowerConnect B Series FCX Configuration Guide 53 1002266 01 PowerConnect B Series FCX hitless stacking 5 ...
Страница 229: ...PowerConnect B Series FCX Configuration Guide 187 53 1002266 01 PowerConnect B Series FCX hitless stacking 5 ...
Страница 230: ...188 PowerConnect B Series FCX Configuration Guide 53 1002266 01 PowerConnect B Series FCX hitless stacking 5 ...
Страница 248: ...206 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IPv6 management commands 7 ...
Страница 346: ...304 PowerConnect B Series FCX Configuration Guide 53 1002266 01 802 1s Multiple Spanning Tree Protocol 8 ...
Страница 374: ...332 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Jumbo frame support 9 ...
Страница 424: ...382 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Virtual Switch Redundancy Protocol VSRP 10 ...
Страница 568: ...526 PowerConnect B Series FCX Configuration Guide 53 1002266 01 CLI examples 14 ...
Страница 588: ...546 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Sample application 15 ...
Страница 674: ...632 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Enabling or disabling layer 2 switching 19 ...
Страница 684: ...642 PowerConnect B Series FCX Configuration Guide 53 1002266 01 VLAN based mirroring 20 ...
Страница 724: ...682 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Reading CDP packets 23 ...
Страница 768: ...726 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Clearing cached LLDP neighbor information 24 ...
Страница 930: ...888 PowerConnect B Series FCX Configuration Guide 53 1002266 01 26 ...
Страница 948: ...906 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Configuring MLD snooping 27 ...
Страница 962: ...920 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Displaying CPU utilization statistics 28 ...
Страница 1022: ...980 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Displaying OSPF information 29 ...
Страница 1142: ...1100 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Clearing diagnostic buffers 30 ...
Страница 1258: ...1216 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Using Secure copy with SSH2 33 ...
Страница 1314: ...1272 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Displaying port security information 35 ...
Страница 1348: ...1306 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Example configurations 36 ...
Страница 1406: ...1364 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IP source guard 39 ...
Страница 1422: ...1380 PowerConnect B Series FCX Configuration Guide 53 1002266 01 SNMP v3 Configuration examples 40 ...