7-29
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
N o t e
For information on syntax details for RADIUS-assigned ACLs, refer to the next
section.
Figure 7-5. Example of Configuring the FreeRADIUS Server To Support ACLs for the Indicated Clients
Example Using HP VSA 63 To Assign IPv6 and/or IPv4 ACLs
The ACL VSA
HP-Nas-Rules-IPv6=1
is used in conjunction with the standard
attribute (
Nas-Filter-Rule
) for ACL assignments filtering both IPv6 and IPv4
traffic inbound from an authenticated client. For example, to use these
attributes to configure a RADIUS-assigned ACL on a FreeRADIUS server to
filter both IPv6 and IPv4 ACL, you would do the following:
1.
Enter the following in the FreeRADIUS
dictionary.hp
file:
•
HP vendor-specific ID
•
ACL VSA for IPv6 ACLs (63)
•
HP-Nas-Rules-IPv6 VALUE setting to specify both IPv4 and IPv6 (1)
Figure 7-6. Example: Configuring the VSA for RADIUS-Assigned IPv6 and IPv4 ACLs in a FreeRADIUS Server
mobilE011 Auth-Type:= Local, User-Password == run10kFast
Nas-FILTER-Rule = “permit in tcp from any to host 10.10.10.101” 80,
Nas-FILTER-Rule += “deny in tcp from any to any” 80,
Nas-FILTER-Rule += “permit in ip from any to any”
08E99C4F0019 Auth-Type:= Local, User-Password == 08E99C4F0019
Nas-FILTER-Rule = “permit in tcp from any to host 10.10.10.101” 80,
Nas-FILTER-Rule += “deny in tcp from any to any” 80,
Nas-FILTER-Rule += “permit in ip from any to any”
Client’s Username (MAC Authentication)
Client’s Username (802.1X or Web Authentication)
Client’s Password (802.1X or Web Authentication)
Note that when the client MAC address is used for authentication, it is used in both
the username and password spaces in the entry.
Client’s Password (MAC Authentication)
VENDOR HP 11
BEGIN-VENDOR HP
ATTRIBUTE HP-Nas-Rules-IPv6 63 INTEGER
END-VENDOR HP
HP Vendor-Specific ID
Note: If
you were also using the RADIUS server to administer 802.1p (CoS) priority and/or Rate-Limiting, you
would also insert the ATTRIBUTE entries for these functions above the END-VENDOR entry.
VSA for RADIUS-Assigned IPv6 ACL
option.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......