Applying A Nas-Id Profile To Port Security - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

A user fails ACL authorization in the following situations:
The device fails to authorize the specified ACL to the user.
The server assigns a nonexistent ACL to the user.
This feature does not apply to users who fail VLAN authorization. The device logs off these users
directly.
To enable the authorization-fail-offline feature:
Step
1.
Enter system view.
2.
Enable the
authorization-fail-offline
feature.

Applying a NAS-ID profile to port security

By default, the device sends its device name in the NAS-Identifier attribute of all RADIUS requests.
A NAS-ID profile enables you to send different NAS-Identifier attribute strings in RADIUS requests
from different VLANs. The strings can be organization names, service names, or any user
categorization criteria, depending on the administrative requirements.
For example, map the NAS-ID companyA to all VLANs of company A. The device will send
companyA in the NAS-Identifier attribute for the RADIUS server to identify requests from any
Company A users.
You can apply a NAS-ID profile to port security globally or on a port. On a port, the device selects a
NAS-ID profile in the following order:
1.
The port-specific NAS-ID profile.
2.
The NAS-ID profile applied globally.
If no NAS-ID profile is applied or no matching binding is found in the selected profile, the device uses
the device name as the NAS-ID.
For more information about the NAS-ID profile configuration, see "Configuring AAA."
To apply a NAS-ID profile to port security:
Step
1.
Enter system view.
2.
Apply a NAS-ID profile.
Command
system-view
port-security authorization-fail
offline
Command
system-view
In system view:
port-security nas-id-profile
profile-name
In interface view:
a. interface interface-type
interface-number
b. port-security
nas-id-profile
profile-name
234
Remarks
N/A
By default, this feature is disabled,
and the device does not log off
users who fail ACL authorization.
Remarks
N/A
By default, no NAS-ID profile is
applied in system view or in
interface view.

Advertisement

Table of Contents
loading

Table of Contents