IPv4 Access Control Lists (ACLs)
Overview
Static Port ACL and Dynamic Port ACL Applications
An IPv4 static port ACL filters any IPv4 traffic inbound on the designated port,
regardless of whether the traffic is switched or routed.
Dynamic (RADIUS-assigned) Port ACL Applications
Dynamic (RADIUS-assigned) port ACLs are configured on RADIUS servers
and, where such servers support configuration for IPv4 traffic filtering, can
be assigned to filter IPv4 traffic inbound from clients authenticated by such
servers. For example, client “A” connects to a given port and is authenticated
by a RADIUS server. Because the server is configured to assign a dynamic ACL
to the port, the IPv4 traffic inbound on the port from client “A” is filtered.
Effect of Dynamic Port ACLs When Multiple Clients Are Using the
Same Port.
Some network configurations may allow multiple clients to
authenticate through a single port where a RADIUS server assigns a separate,
dynamic port ACL in response to each client’s authentication on that port. In
such cases, a given client’s inbound traffic will be allowed only if the RADIUS
authentication response for that client includes a dynamic port ACL. For
example, in figure 9-1 (below), clients A through D authenticate through the
same port (B1) on the ProCurve-A switch.
Unmanaged
Switch
RADIUS
Server
Client D
Client C
ProCurve-A
Client A
Client B
10.100.0.0
LAN
Port B1
Figure 9-1. Example of Multiple Clients Authenticating Through a Single Port
In this case, the RADIUS server must be configured to assign a dynamic port
ACL to port B1 each time any of the clients authenticates on the port.
9-15
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...