7-11
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
Configuring and Using Dynamic
(RADIUS-Assigned) Access Control
Lists
Introduction
A RADIUS-assigned ACL is configured on a RADIUS server and dynamically
assigned by the server to filter IP traffic from a specific client after the client
is authenticated by the server.
The information in this section describes how to apply RADIUS-assigned ACLs
on the switch, and assumes a general understanding of ACL structure and
operation. If you need information on ACL filtering criteria, design, and
operation, refer to the following:
■
the chapter titled “IPv4 Access Control Lists (ACLs)”, in this manual
■
the chapter titled “IPv6 Access Control Lists (ACLs)” in the latest
IPv6
Configuration Guide
for your switch
Terminology
ACE:
See Access Control Entry, below.
Access Control Entry (ACE):
An ACE is a policy consisting of a packet-
handling action and criteria to define the packets on which to apply the
action. For ACE details, refer to “ACE Syntax in RADIUS Servers” on page
7-25
Access Control List (ACL):
A list (or set) consisting of one or more
explicitly configured Access Control Entries (ACEs) and terminating with
an implicit “deny”
default which drops any IP packets that do not have a
match with any explicit ACE in the named ACL. An ACL can be applied in
the following ways:
•
VACL: an ACL assigned to filter inbound traffic on a specific VLAN
configured on the switch
•
Static Port ACL: an ACL assigned to filter inbound traffic on a specific
switch port
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......