Acl Assignment Configuration Example - H3C S5500-SI Series Operation Manual

Hide thumbs Also See for S5500-SI Series:
Table of Contents

Advertisement

ACL Assignment Configuration Example

Network requirements
As shown in
Figure
MAC authentication to access the Internet.
Specify to use the MAC address of a user as the username and password for MAC authentication
of the user.
Configure the RADIUS server to assign ACL 3000.
On port GigabitEthernet 1/0/1 of the switch, enable MAC authentication and configure ACL 3000.
After the host passes MAC authentication, the RADIUS server assigns ACL 3000 to port
GigabitEthernet 1/0/1 of the switch. As a result, the host can access the Internet but cannot access the
FTP server, whose IP address is 10.0.0.1.
Figure 1-3 Network diagram for ACL assignment
Configuration procedure
Make sure that there is a route available between the RADIUS server and the switch.
In this example, the switch uses the default username type (user MAC address) for MAC
authentication. Therefore, you need to add the username and password of each user on the
RADIUS server correctly.
You need to configure the RADIUS server to assign ACL 3000 as the authorization ACL.
# Configure the RADIUS scheme.
<Sysname> system-view
[Sysname] radius scheme 2000
[Sysname-radius-2000] primary authentication 10.1.1.1 1812
[Sysname-radius-2000] primary accounting 10.1.1.2 1813
[Sysname-radius-2000] key authentication abc
[Sysname-radius-2000] key accounting abc
[Sysname-radius-2000] user-name-format without-domain
[Sysname-radius-2000] quit
1-3, a host is connected to port GigabitEthernet 1/0/1 of the switch and must pass
1-9

Advertisement

Chapters

Table of Contents
loading

Table of Contents