Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
Configuring and Using
RADIUS-Assigned Access Control Lists
Introduction
A RADIUS-assigned ACL is configured on a RADIUS server and dynamically
assigned by the server to filter traffic entering the switch through a specific
port after the client is authenticated by the server. Note that client authenti
cation can be enhanced by using ProCurve Manager with the optional IDM
application. (Refer to “Optional PCM and IDM Applications” on page 6-3.)
The information in this section describes how to apply RADIUS-assigned ACLs
on the switch, and assumes a general understanding of ACL structure and
operation. If you need information on ACL filtering criteria, design, and
operation, please refer to chapter 9, “IPv4 Access Control Lists (ACLs)”.
Terminology
ACE:
See Access Control Entry, below.
Access Control Entry (ACE):
An ACE is a policy consisting of a packet-
handling action and criteria to define the packets on which to apply the
action. For RADIUS-assigned ACLs, the elements composing the ACE
include:
•
permit
or
drop
(action)
•
in <
ip-packet-type
> from any
(source)
•
to < ip-address [/ mask ] | any >
(destination)
•
[
port-#
]
(optional TCP or UDP application port numbers used when
the packet type is TCP or UDP)
ACL:
See Access Control List, below.
Access Control List (ACL):
A list (or set) consisting of one or more
explicitly configured Access Control Entries (ACEs) and terminating with
an implicit “deny” default which drops any IP packets that do not have a
match with any explicit ACE in the named ACL. An ACL can be “standard”
or “extended”. See “Standard ACL” and “Extended ACL”. Both can be
applied in any of the following ways:
•
Static Port ACL: an ACL assigned to filter inbound traffic on a specific
switch port
6-9
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...