7-30
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
2.
Enter the switch IPv4 address, NAS (Network Attached Server) type, and
the key used in the FreeRADIUS
clients.conf
file. For example, if the switch
IP address is 10.10.10.125 and the key (“secret”) is “1234”, you would enter
the following in the server’s
clients.conf
file:
Figure 7-7. Example of Switch Identity Information for a FreeRADIUS Application
3.
For a given client username/password pair, create an ACL by entering one
or more IPv6 and IPv4 ACEs in the FreeRADIUS “users” file. Remember
that the ACL you create to filter both IPv4 and IPv6 traffic automatically
includes an implicit
deny in ip from any to any
ACE at the end of the ACL
(to drop any IPv4 and IPv6 traffic that is not explicitly permitted or denied
by the ACL). For example, suppose that you wanted to create ACL support
for a client having a username of “Admin01” and a password of “myAuth9”.
The ACL in this example must achieve the following:
•
Permit http (TCP port 80) traffic from the client to the device at
FE80::a40.
•
Deny http (TCP port 80) traffic from the client to all other IPv6
addresses.
•
Permit http (TCP port 80) traffic from the client to the device at
10.10.10.117.
•
Deny http (TCP port 80) traffic from the client to all other IPv4
addresses.
•
Deny Telnet (TCP port 23) traffic from the client to any IPv4 or IPv6
addresses.
•
Permit all other IPv4 and IPv6 traffic from the client to all other
devices.
To configure the above ACL, you would enter the username/password and
ACE information shown in figure 7-8 into the FreeRADIUS “users” file.
client 10.10.18.12
nastype = other
secret = 1234
Note:
The
key
configured in the switch and the
secret
configured in the RADIUS server
supporting the switch must be identical. Refer
to the chapter titled “RADIUS Authentication
and Accounting” in the latest
Access Security
Guide
for your switch.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......