10-17
IPv4 Access Control Lists (ACLs)
Overview
RADIUS-Assigned (Dynamic) Port ACL Applications
N o t e
IPv6 support is available for RADIUS-assigned port ACLs configured to filter
inbound IPv4 and IPv6 traffic from an authenticated client. Also, the implicit
deny in RADIUS-assigned ACLs applies to both IPv4 and IPv6 traffic inbound
from the client. For information on enabling RADIUS-assigned ACLs, refer to
the chapter titled “Configuring RADIUS Support for Switch Services” in this
guide.
Dynamic (RADIUS-assigned) port ACLs are configured on RADIUS servers
and can be configured to filter IPv4 and IPv6 traffic inbound from clients
authenticated by such servers. For example, in figure 10-3 client “A” connects
to a given port and is authenticated by a RADIUS server. Because the server
is configured to assign a dynamic ACL to the port, the IPv4 and IPv6 traffic
inbound on the port from client “A” is filtered. (See also “Operating Notes” on
page 10-18.)
Effect of RADIUS-assigned ACLs When Multiple Clients Are Using the
Same Port.
Some network configurations may allow multiple clients to
authenticate through a single port where a RADIUS server assigns a separate,
RADIUS-assigned ACL in response to each client’s authentication on that port.
In such cases, a given client’s inbound traffic will be allowed only if the
RADIUS authentication response for that client includes a RADIUS-assigned
ACL. For example, in figure 10-3 (below), clients A through D authenticate
through the same port (1).
Figure 10-3. Example of Multiple Clients Authenticating Through a Single Port
In this case, the RADIUS server must be configured to assign a RADIUS-
assigned ACL to port B1 each time any of the clients authenticates on the port.
Unmanaged
Switch
RADIUS
Server
Client D
Client C
3800 Switch
Client A
Client B
10.100.0.0
LAN
Port 1
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......