Configuring The Switch To Support Dynamic Port; Acls - ProCurve 2610 Manual

2610 / 2610-pwr series
Table of Contents

Advertisement

Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
Note
6-20
are not explicitly denied, you must configure permit in ip from any to any as the
last explicit ACE in the ACL. This pre-empts the implicit deny in ip from any to
any ACE and permits packets not explicitly permitted or denied by earlier
ACEs in the list.

Configuring the Switch To Support Dynamic Port

ACLs

An ACL configured in a RADIUS server is identified by the authentication
credentials of the client or group of clients the ACL is designed to support.
When a client authenticates with credentials associated with a particular ACL,
the switch applies that ACL to the switch port the client is using. To enable
the switch to forward a client's credentials to the RADIUS server, you must
first configure RADIUS operation and an authentication method on the switch.
1. Configure RADIUS operation on the switch:
Syntax: radius-server host < ip-address > key < key-string >
This command configures the IP address and encryption key of a
RADIUS server. The server should be accessible to the switch and
configured to support authentication requests from clients using the
switch to access the network. For more on RADIUS configuration,
refer to chapter 5, "RADIUS Authentication and Accounting".
2. Configure RADIUS network accounting on the switch (optional). RADIUS
network accounting is necessary to retrieve counter information if the cnt
(counter) option is included in any of the ACEs configured on the RADIUS
server.
Syntax: aaa accounting network < start-stop | stop-only > radius
Refer to the documentation provided with your RADIUS server for infor­
mation on how the server receives and manages network accounting
information, and how to perform any configuration steps necessary to
enable the server to support network accounting data from the switch.
3. Configure an authentication method. Options include 802.1X, Web
authentication, and MAC authentication. (You can configure 802.1X and
either Web or MAC authentication to operate simultaneously on the same
ports.)
802.1X Option:

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents