7-43
Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
Event Log Messages
Please see the
Event Log Message Reference Guide
for information about
Event Log messages.
Causes of Client Deauthentication Immediately
After Authenticating
■
ACE formatted incorrectly in the RADIUS server
•
“from”, “any”, or “to” keyword missing
•
An IPv4 or IPv6 protocol number in the ACE exceeds 255.
•
An optional UDP or TCP port number is invalid, or a UDP/TCP port
number is specified when the protocol is neither UDP or TCP.
■
A RADIUS-assigned ACL limit has been exceeded.
•
An ACE in the ACL for a given authenticated client exceeds 80
characters.
•
The TCP/UDP port-range quantity of 14 per slot or port group has been
exceeded.
•
The rule limit of 3048 per slot or port group has been exceeded.
■
An IPv6 ACE has been received on a port and either the
HP-Nas-Rules-
IPv6
attribute is missing or
HP-Nas-Rules-IPv6=2
is configured. Refer to
table 7-7 on page 7-24 for more on this attribute.
Monitoring Shared Resources
Currently active, RADIUS-based authentication sessions (including HP PMC
IDM client sessions) using RADIUS-assigned ACLs share internal switch
resources with several other features. The switch provides ample resources
for all features. However, if the internal resources do become fully subscribed,
new RADIUS-based sessions using RADIUS-assigned ACLs cannot be authen-
ticated until the necessary resources are released from other applications.
■
For information on determining the current resource availability and
usage, refer to the appendix titled “Monitoring Resources” in the
Management and Configuration Guide
for your switch.
■
For a summary of ACL resource limits, refer to the appendix covering
scalability in the latest
Management and Configuration Guide
for
your switch.
Содержание HP ProCurve Series 6600
Страница 2: ......
Страница 6: ...iv ...
Страница 26: ...xxiv ...
Страница 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Страница 204: ...4 72 Web and MAC Authentication Client Status ...
Страница 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Страница 756: ...16 8 Key Management System Configuring Key Chain Management ...
Страница 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Страница 777: ......