Acl Assignment; User Profile Assignment - H3C SR8800-F Configuration Manual

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

is not assigned to the critical VLAN. For more information about the authentication methods, see
"Configuring
Table 11
shows the way that the network access device handles critical VLANs for MAC
authentication users.
Table 11 VLAN manipulation
Authentication status
A user fails MAC authentication because all the
RADIUS servers are unreachable.
A user in the MAC authentication critical VLAN
fails MAC authentication for any reason other
than server unreachable.
A user in the MAC authentication critical VLAN
passes MAC authentication.

ACL assignment

You can specify an authorization ACL in the user account for a MAC authentication user to control
the user's access to network resources. After the user passes MAC authentication, the
authentication server (local or remote) assigns the authorization ACL to the access port of the user.
The ACL will filter traffic for this user. You must configure ACL rules for the authorization ACL on the
access device for the ACL assignment feature.
To ensure a successful ACL assignment, make sure the ACL does not contain rules that match
source MAC addresses.
To change the access control criteria for the user, you can use one of the following methods:
Modify ACL rules on the access device.
Specify another authorization ACL on the authentication server.
For more information about ACLs, see ACL and QoS Configuration Guide.

User profile assignment

You can specify a user profile in the user account for a MAC authentication user to control the user's
access to network resources. After the user passes MAC authentication, the authentication server
assigns the user profile to the user to filter traffic for this user. The authentication server can be the
local access device or a RADIUS server. In either case, you must configure the user profile on the
access device.
To change the user's access permissions, you can use one of the following methods:
Modify the user profile configuration on the access device.
Specify another user profile for the user on the authentication server.
AAA."
VLAN manipulation
The device maps the MAC address of the user to the MAC
authentication critical VLAN.
The user is still in the MAC authentication critical VLAN if
the user fails MAC reauthentication because all the
RADIUS servers are unreachable.
If no MAC authentication critical VLAN is configured, the
device maps the MAC address of the user to the PVID of
the port.
If a guest VLAN has been configured, the device maps the
MAC address of the user to the guest VLAN.
If no guest VLAN is configured, the device maps the MAC
address of the user to the PVID of the port.
The device remaps the MAC address of the user to the
authorization VLAN assigned by the authentication server.
If no authorization VLAN is configured for the user on the
authentication server, the device remaps the MAC
address of the user to the PVID of the access port.
214

Advertisement

Table of Contents
loading

Table of Contents