Overview Of Radius-Assigned, Dynamic Acls - HP E3800-24G-PoE+-2SFP+ Access Security Manual

Switch software
Hide thumbs Also See for E3800-24G-PoE+-2SFP+:
Table of Contents

Advertisement

Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
7-14
VLAN ACL (VACL): An ACL applied to traffic entering the switch on a given
VLAN interface. See also "Access Control List".
VSA (Vendor-Specific-Attribute): A value used in a RADIUS-based config-
uration to uniquely identify a networking feature that can be applied to a
port on a given vendor's switch during an authenticated client session.
Wildcard: The part of a mask that indicates the bits in a packet's IP addressing
that do not need to match the corresponding bits specified in an ACL. See
also ACL Mask on page 7-12.

Overview of RADIUS-Assigned, Dynamic ACLs

RADIUS-assigned ACLs enhance network and switch management access
security and traffic control by permitting or denying authenticated client
access to specific network resources and to the switch management interface.
This includes preventing clients from using TCP or UDP applications, ICMP
packet types, and IGMP (IPv4 only) if you do not want their access privileges
to include these capabilities.
Traffic Applications
The switch supports RADIUS-assigned ACLs for the following traffic applica-
tions:
inbound IPv4 traffic only
inbound IPv4 and IPv6 traffic
This feature is designed for use on the network edge to accept RADIUS-
assigned ACLs for Layer-3 filtering of IP traffic entering the switch from
authenticated clients. A given RADIUS-assigned ACL is identified by a unique
username/password pair or client MAC address, and applies only to IP traffic
entering the switch from clients that authenticate with the required, unique
credentials. The switch allows multiple RADIUS-assigned ACLs on a given
port, up to the maximum number of authenticated clients allowed on the port.
Also, a RADIUS-assigned ACL for a given client's traffic can be assigned
regardless of whether other ACLs assigned to the same port are statically
configured on the switch.
A RADIUS-assigned ACL filters IP traffic entering the switch from the client
whose authentication caused the ACL assignment. Filter criteria is based on:
destination address
IPv4 or IPv6 traffic type (such as TCP and UDP traffic)

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents