7-34
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
Configuration Notes
Explicitly Permit IPv4 and IPv6 Traffic From an Authenticated
Client.
This option for ending a RADIUS-assigned ACL permits all of the
client’s inbound IPv4 and IPv6 traffic not previously permitted or denied.
Nas-filter-Rule += permit in ip from any to any
HP-Nas-Rules-IPv6 = 1
(Refer to table 7-7 on page 7-23 for information on the above attributes.)
Explicitly Permit Only the IPv4 Traffic From an Authenticated Client.
Any of the following three options for ending a RADIUS-assigned ACL explic-
itly permit all of the client’s inbound IPv4 traffic not previously permitted or
denied. These options also deny any of the client’s IPv6 traffic not previously
permitted or denied.
■
Nas-filter-Rule += permit in ip from any to any
(Using this attribute to permit IPv4 traffic from the client while denying
any IPv6 traffic from the client assumes that
HP-Nas-Rules-IPv6 = 1
does not
exist elsewhere in the ACL. Refer to table 7-7 on page 7-23 for more on
HP-Nas-Rules-IPv6.
)
■
HP-Nas-Filter-Rule += permit in ip from any to any
■
Nas-filter-Rule += permit in ip from any to any
HP-Nas-Rules-IPv6 = 2
Explicitly Denying Inbound Traffic From an Authenticated Client.
Any of the following three options for ending a RADIUS-assigned ACL explic-
itly deny all of the client’s inbound IPv4 and IPv6 traffic not previously
permitted or denied.
■
Nas-filter-Rule += deny in ip from any to any
■
HP-Nas-Filter-Rule += deny in ip from any to any
■
Nas-filter-Rule += deny in ip from any to any
HP-Nas-Rules-IPv6 = 2
Implicitly Denying Any IP Traffic.
For any packet being filtered by a
RADIUS-assigned ACL, there will always be a match. That is, any packet that
does not have a match with an explicit permit or deny ACE in the list will
match with the implicit “deny any any” ACE automatically included at the end
of the ACL. That is, a RADIUS-assigned ACL includes an implicit
deny in ip from
any to any
ACE at the end of the ACL to deny any IPv4 and IPv6 traffic not
previously permitted or denied.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......