D-Link DWS-1008 User Manual page 305

Wireless 8 port switch with poe
Hide thumbs Also See for DWS-1008:
Table of Contents

Advertisement

DWS-1008 User's Manual
Assigning a Security ACL to a User or a Group
Once a security access control list (ACL) is defined and committed, it can be applied
dynamically and automatically to users and user groups through the 802.1X authentication
and authorization process. When you assign a Filter-Id attribute to a user or group, the security
ACL name value is entered as an authorization attribute into the user or group record in the
local database or RADIUS server.
Note: If the Filter-Id value returned through the authentication and authorization process
does not match the name of a committed security ACL in the DWS-1008 switch, the user fails
authorization and cannot be connected.
Assigning a Security ACL Locally
To use the local DWS-1008 switch database to restrict a user, a MAC user, or a group of
users or MAC users to the permissions stored within a committed security ACL, use the
following commands:
Security ACL Target
User authenticated by a
password
Group of users authenticated by
a password
User authenticated by a MAC
address
Group of users authenticated by
a MAC address
You can set filters for incoming and outgoing packets:
• Use acl-name.in to filter traffic that enters the switch from users via an DWL-8220AP
access port or wired authentication port, or from the network via a network port.
• Use acl-name.out to filter traffic sent from the switch to users via an DWL-8220AP
access port or wired authentication port, or from the network via a network port.
For example, the following command applies security ACL acl-101 to packets coming into the
DWS-1008 switch from user Jose:
DWS-1008# set user Jose attr filter-id acl-101.in
success: change accepted.
D-Link Systems, Inc.
Commands
set user username attr filter-id acl-name.in
set user username attr filter-id acl-name.out
set usergroup groupname attr filter-id acl-name.in
set usergroup groupname attr filter-id acl-name.out
set mac-user username attr filter-id acl-name.in
set mac-user username attr filter-id acl-name.out
set mac-usergroup groupname attr filter-id acl-name.
in
set mac-usergroup groupname attr filter-id acl-name.
out
Configuring AAA for Network Users
300

Advertisement

Table of Contents
loading

Table of Contents