7-15
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
Overview of RADIUS-Assigned, Dynamic ACLs
RADIUS-assigned ACLs enhance network and switch management access
security and traffic control by permitting or denying authenticated client
access to specific network resources and to the switch management interface.
This includes preventing clients from using TCP or UDP applications, ICMP
packet types, and IGMP (IPv4 only) if you do not want their access privileges
to include these capabilities.
Traffic Applications
Beginning with software release K.14.01, the switch supports RADIUS-
assigned ACLs for the following traffic applications:
■
inbound IPv4 traffic only
■
inbound IPv4 and IPv6 traffic
This feature is designed for use on the network edge to accept RADIUS-
assigned ACLs for Layer-3 filtering of IP traffic entering the switch from
authenticated clients. A given RADIUS-assigned ACL is identified by a unique
username/password pair or client MAC address, and applies only to IP traffic
entering the switch from clients that authenticate with the required, unique
credentials. The switch allows multiple RADIUS-assigned ACLs on a given
port, up to the maximum number of authenticated clients allowed on the port.
Also, a RADIUS-assigned ACL for a given client’s traffic can be assigned
regardless of whether other ACLs assigned to the same port are statically
configured on the switch.
A RADIUS-assigned ACL filters IP traffic entering the switch from the client
whose authentication caused the ACL assignment. Filter criteria is based on:
■
destination address
■
IPv4 or IPv6 traffic type (such as TCP and UDP traffic)
Implementing the feature requires:
■
RADIUS authentication using the 802.1X, Web authentication, or MAC
authentication available on the switch to provide client authentica-
tion services
■
configuring one or more ACLs on a RADIUS server (instead of the
switch), and assigning each ACL to the username/password pair or
MAC address of the client(s) you want the ACLs to support
Using RADIUS to dynamically apply ACLs to clients on edge ports enables the
Содержание HP ProCurve Series 6600
Страница 2: ......
Страница 6: ...iv ...
Страница 26: ...xxiv ...
Страница 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Страница 204: ...4 72 Web and MAC Authentication Client Status ...
Страница 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Страница 756: ...16 8 Key Management System Configuring Key Chain Management ...
Страница 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Страница 777: ......