7-17
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
Caution Regarding
the Use of IPv4
Source Routing
IPv4 source routing is enabled by default on the switch and can be used to
override IPv4 ACLs. For this reason, if you are using IPv4 ACLs to enhance
network security, the recommended action is to use the
no ip source-route
command to disable source routing on the switch. (If source routing is
disabled in the running-config file, the
show running
command includes “
no ip
source-route
” in the running-config file listing.)
Allows one RADIUS-assigned ACL per authenticated client
on a port. (Each such ACL filters traffic from a different,
authenticated client.)
Note:
The switch provides ample resources for supporting
RADIUS-assigned ACLs and other features. However, the
actual number of ACLs supported depends on the switch’s
current feature configuration and the related resource
requirements. For more information, refer to the appendix
titled “Monitoring Resources” in the
Management and
Configuration Guide
for your switch.
Simultaneously supports all of the following static
assignments affecting a given port:
• IPv4 traffic:
– inbound RACL
– outbound RACL
– VACL
– static port ACL
• IPv6 traffic:
– VACL
– static port ACL
Supports IPv6 ACLs and IPv4 extended ACLs. (Refer to
“Terminology” on page 7-11.)
Supports IPv6 ACLs and standard, extended, and
connection-rate IPv4 ACLs. (Refer to “Configuring and
Applying Connection-Rate ACLs” on page 3-17.)
A given RADIUS-assigned ACL operates on a port to filter
only the IP traffic entering the switch from the authenticated
client corresponding to that ACL, and does not filter IP traffic
inbound from other authenticated clients.(The traffic source
is not a configurable setting.)
An RACL
applied to inbound traffic on a VLAN filters routed
IPv4 traffic entering the switch through a port on that VLAN,
as well as any inbound traffic having a DA on the switch
itself. An RACL can be applied to outbound IPv4 traffic on a
VLAN to filters routed IPv4 traffic leaving the switch through
a port on that VLAN (and includes routed IPv4 traffic
generated by the switch itself).
A VACL
can be applied on a VLAN to filter either IPv4 or IPv6
traffic entering the switch through a port on that VLAN.
A static port ACL
can be applied on a port to filters either
IPv4 or IPv6 traffic entering the switch through that port.
Requires client authentication by a RADIUS server
configured to dynamically assign an ACL to a client on a
switch port, based on client credentials.
No client authentication requirement.
ACEs allow a counter (
cnt
) option that causes a counter to
increment when there is a packet match.
The show statistics command includes options for
displaying the packet match count. (Refer to “Monitoring
Static ACL Performance” on page 10-117.)
Also, ACEs allow a
log
option that generates a log message
whenever there is a packet match with a “deny” ACE.
RADIUS-Assigned ACLs
Static Port and VLAN ACLs
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......