7-33
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
•
Permit http (TCP port 80) traffic from the client to the device at
10.10.10.117.
•
Deny http (TCP port 80) traffic from the client to all other IPv4
addresses.
•
Deny Telnet (TCP port 23) traffic from the client to any IPv4 address.
•
Permit all other IPv4 traffic from the client to all other devices.
To configure the above ACL, you would enter the username/password and
ACE information shown in figure 7-11 into the FreeRADIUS “users” file.
Figure 7-11. Example of Configuring a FreeRADIUS Server To Filter IPv4 Traffic for a Client Using the Correct
Username and Password Credentials.
User-10 Auth-Type:= Local, User-Password == auth7X
HP-Nas-Rules-IPv6 = 1,
HP-Nas-filter-Rule = “permit in tcp from any to 10.10.10.117 80”,
HP-Nas-filter-Rule += “deny in tcp from any to any 80”,
HP-Nas-filter-Rule += “deny in tcp from any to any 23”,
HP-Nas-filter-Rule += “permit in ip from any to any”
Client’s Username (802.1X or Web Authentication)
Client’s Password (802.1X or Web Authentication)
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......