Example Using Hp Vsa 63 To Assign Ipv6 And/Or Ipv4 Acls - HP 3500yl Series Access Security Manual

Switch software
Hide thumbs Also See for 3500yl Series:
Table of Contents

Advertisement

Configuring RADIUS Server Support for Switch Services
Configuring and Using Dynamic (RADIUS-Assigned) Access Control Lists
Note
Client's Username (802.1X or Web Authentication)
mobilE011 Auth-Type:= Local, User-Password == run10kFast
Nas-FILTER-Rule = "permit in tcp from any to host 10.10.10.101" 80,
Nas-FILTER-Rule += "deny in tcp from any to any" 80,
Nas-FILTER-Rule += "permit in ip from any to any"
Client's Username (MAC Authentication)
08E99C4F0019 Auth-Type:= Local, User-Password == 08E99C4F0019
Nas-FILTER-Rule = "permit in tcp from any to host 10.10.10.101" 80,
Nas-FILTER-Rule += "deny in tcp from any to any" 80,
Nas-FILTER-Rule += "permit in ip from any to any"
Figure 7-5. Example of Configuring the FreeRADIUS Server To Support ACLs for the Indicated Clients
VENDOR
BEGIN-VENDOR
ATTRIBUTE
END-VENDOR
Note: If you were also using the RADIUS server to administer 802.1p (CoS) priority and/or Rate-Limiting, you
would also insert the ATTRIBUTE entries for these functions above the END-VENDOR entry.
Figure 7-6. Example: Configuring the VSA for RADIUS-Assigned IPv6 and IPv4 ACLs in a FreeRADIUS Server
7-30
For information on syntax details for RADIUS-assigned ACLs, refer to the next
section.
Note that when the client MAC address is used for authentication, it is used in both
the username and password spaces in the entry.

Example Using HP VSA 63 To Assign IPv6 and/or IPv4 ACLs

The ACL VSA HP-Nas-Rules-IPv6=1 is used in conjunction with the standard
attribute (Nas-Filter-Rule) for ACL assignments filtering both IPv6 and IPv4
traffic inbound from an authenticated client. For example, to use these
attributes to configure a RADIUS-assigned ACL on a FreeRADIUS server to
filter both IPv6 and IPv4 ACL, you would do the following:
Enter the following in the FreeRADIUS dictionary.hp file:
1.
HP vendor-specific ID
ACL VSA for IPv6 ACLs (63)
HP-Nas-Rules-IPv6 VALUE setting to specify both IPv4 and IPv6 (1)
HP
11
HP
HP-Nas-Rules-IPv6 63 INTEGER
HP
Client's Password (802.1X or Web Authentication)
Client's Password (MAC Authentication)
HP Vendor-Specific ID
VSA for RADIUS-Assigned IPv6 ACL
option.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents