7-8
Configuring RADIUS Server Support for Switch Services
RADIUS Server Configuration for CoS (802.1p Priority) and Rate-Limiting
For example, suppose port 4 has been statically configured from the CLI with
the following:
■
802.1p priority: 7
■
inbound rate-limit: 50 percent
■
outbound rate-limit: 50 percent
The above, statically configured, per-port priority and inbound rate-limit
settings will not apply to any clients who authenticate and receive different
inbound priority and rate-limit settings from the RADIUS server. If the RADIUS
server also assigns an outbound rate-limit setting, which is applied per-port
instead of per-client, then the outbound traffic from the port to all connected
clients will be rate-limited according to the value set by the server for the most
recently authenticated client. Thus, if client “X” authenticates with Web-Auth
on port 4 with a RADIUS server that assigns a priority of 3, an inbound rate-
limit of 10,000 kbps, and an outbound rate-limit of 50,000 kbps, then:
■
The inbound traffic from client “X” will be subject to a priority of 3
and inbound rate-limit of 10,000 kbps. Traffic from other clients using
the port will not be affected by these values.
■
The combined rate-limit outbound for all clients using the port will
be 50,000 kbps until either all client sessions end or another client
authenticates and receives a different outbound rate-limit.
web-based
[
port-list
] clients detail
displays, for a Web authen-
ticated client (Web-Auth), the status of RADIUS-assignment
details for that client.. (Refer to “Show Commands for Web
Authentication” on page 4-26.)
mac-based
[
port-list
] clients detail
displays, for a MAC authen-
ticated client (MAC-Auth), the status of RADIUS-assignment
details for that client. (Refer to “Show Commands for MAC-
Based Authentication” on page 4-65.)
authenticator
[
port-list
] clients detail
displays, for an 802.1X-
authenticated client, the status of RADIUS-assignment
details for that client.. (Refer to “Show Commands for Port-
Access Authenticator” on page 13-55.)
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......