10-3
IPv4 Access Control Lists (ACLs)
Overview of Options for Applying IPv4 ACLs on the Switch
Overview of Options for Applying IPv4
ACLs on the Switch
To apply IPv4 ACL filtering, assign a configured IPv4 ACL to the interface on
which you want traffic filtering to occur. VLAN and routed IPv4 traffic ACLs
can be applied statically using the switch configuration. Port traffic ACLs can
be applied either statically or dynamically (using a RADIUS server).
Static ACLS
Static ACLs are configured on the switch. To apply a static ACL, you must
assign it to an interface (VLAN or port). The switch supports three static ACL
applications:
Routed IPv4 Traffic ACL (RACL).
An RACL is an ACL configured on a
VLAN to filter routed traffic entering or leaving the switch on that interface,
as well as traffic having a destination on the switch itself. (Except for filtering
traffic to an address on the switch itself, RACLs can operate only while IPv4
routing is enabled. Refer to “Notes on IPv4 Routing” on page 10-24.)
VLAN ACL (VACL).
A VACL is an ACL configured on a VLAN to filter traffic
entering the switch on that VLAN interface and having a destination on the
same VLAN.
Static Port ACL.
A static port ACL is an ACL configured on a port to filter
traffic entering the switch on that port, regardless of whether the traffic is
routed, switched, or addressed to a destination on the switch itself.
RADIUS-Assigned ACLs
A RADIUS-assigned ACL is configured on a RADIUS server for assignment to
a given port when the server authenticates a specific client on that port. When
the server authenticates a client associated with that ACL, the ACL is assigned
to the port the client is using. The ACL then filters the IP traffic received
inbound on that port from the authenticated client. If the RADIUS server
supports both IPv4 and IPv6 ACEs, then the ACL assigned by the server can
be used to filter both traffic types, or filter IPv4 traffic and drop IPv6 traffic.
When the client session ends, the ACL is removed from the port. The switch
allows as many RADIUS-assigned ACLs on a port as it allows authenticated
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......