Assigning A Security Acl To A User Or A Group - 3Com 3CRWX120695A, 3CRWX440095A Configuration Manual

Wireless lan switch and controller
Table of Contents

Advertisement

Assigning a Security
ACL to a User or a
Group
Once a security access control list (ACL) is defined and committed, it can
be applied dynamically and automatically to users and user groups
through the 802.1X authentication and authorization process. When you
assign a Filter-Id attribute to a user or group, the security ACL name value
is entered as an authorization attribute into the user or group record in
the local WX database or RADIUS server.
If the Filter-Id value returned through the authentication and
authorization process does not match the name of a committed security
ACL in the WX, the user fails authorization and cannot be connected.
(For details about security ACLs, see Chapter 11, "Configuring and
Managing Security ACLs," on page 231.)
Assigning a Security ACL Locally
To use the local WX database to restrict a user, a MAC user, or a group of
users or MAC users to the permissions stored within a committed security
ACL, use the commands shown in Table 33.
Table 33 Commands for Assigning a Security ACL Locally
Security ACL Target Commands
User authenticated
by a password
Group of users
authenticated by a
password
User authenticated
by a MAC address
Group of users
authenticated by a
MAC address
You can set filters for incoming and outgoing packets:
Use acl-name.in to filter traffic that enters the WX switch from users
via a MAP access port or wired authentication port, or from the
network via a network port.
Use acl-name.out to filter traffic sent from the WX switch to users via
a MAP access port or wired authentication port, or from the network
via a network port.
Assigning Authorization Attributes
set user username attr filter-id acl-name.in
set user username attr filter-id acl-name.out
set usergroup groupname attr filter-id acl-name.in
set usergroup groupname attr filter-id acl-name.out
set mac-user username attr filter-id acl-name.in
set mac-user username attr filter-id acl-name.out
set mac-usergroup groupname attr filter-id acl-name.in
set mac-usergroup groupname attr filter-id acl-name.out
319

Advertisement

Table of Contents
loading

Table of Contents