Overview Of Options For Applying Ipv4 Acls On The Switch; Static Acls; Radius-Assigned Acls - HP 3500yl Series Access Security Manual

Switch software
Hide thumbs Also See for 3500yl Series:
Table of Contents

Advertisement

IPv4 Access Control Lists (ACLs)

Overview of Options for Applying IPv4 ACLs on the Switch

Overview of Options for Applying IPv4
ACLs on the Switch
To apply IPv4 ACL filtering, assign a configured IPv4 ACL to the interface on
which you want traffic filtering to occur. VLAN and routed IPv4 traffic ACLs
can be applied statically using the switch configuration. Port traffic ACLs can
be applied either statically or dynamically (using a RADIUS server).

Static ACLS

Static ACLs are configured on the switch. To apply a static ACL, you must
assign it to an interface (VLAN or port). The switch supports three static ACL
applications:
Routed IPv4 Traffic ACL (RACL). An RACL is an ACL configured on a
VLAN to filter routed traffic entering or leaving the switch on that interface,
as well as traffic having a destination on the switch itself. (Except for filtering
traffic to an address on the switch itself, RACLs can operate only while IPv4
routing is enabled. Refer to "Notes on IPv4 Routing" on page 10-24.)
VLAN ACL (VACL). A VACL is an ACL configured on a VLAN to filter traffic
entering the switch on that VLAN interface and having a destination on the
same VLAN.
Static Port ACL. A static port ACL is an ACL configured on a port to filter
traffic entering the switch on that port, regardless of whether the traffic is
routed, switched, or addressed to a destination on the switch itself.

RADIUS-Assigned ACLs

A RADIUS-assigned ACL is configured on a RADIUS server for assignment to
a given port when the server authenticates a specific client on that port. When
the server authenticates a client associated with that ACL, the ACL is assigned
to the port the client is using. The ACL then filters the IP traffic received
inbound on that port from the authenticated client. If the RADIUS server
supports both IPv4 and IPv6 ACEs, then the ACL assigned by the server can
be used to filter both traffic types, or filter IPv4 traffic and drop IPv6 traffic.
When the client session ends, the ACL is removed from the port. The switch
allows as many RADIUS-assigned ACLs on a port as it allows authenticated
10-3

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents