Downloadable Acls - Cisco WS-C6506 Software Manual

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Downloadable ACLs

Display the PBF configuration commands.
Step 5
Console> (enable) show run
<SNIP>
!
#security ACLs
clear security acl all
#pbf set
set pbf mac 00-0d-65-35-ed-83
#set pbf client
set pbf client CLIENT-TEST 10.0.0.10 00-00-11-11-22-22 10
#set pbf gw
set pbf gw GATEWAY-TEST 10.0.0.100 255.255.255.0 11-11-22-22-33-03 3
#set pbf-map
set pbf-map CLIENT-TEST GATEWAY-TEST
#
commit security acl all
!
<SNIP>
Console> (enable)
Downloadable ACLs
Downloadable ACLs are a set of ACEs that are configured on a RADIUS server. Downloadable ACLs
are downloaded during authentication of a NAC feature such as Dot1x, mac-auth, LPIP, or web-auth.
Downloadable ACLs are a port-based feature. You will need to configure the security ACL so that it is
port based and map an ACL with an include keyword to the port. Do not reconfigure the security ACL
with the include keyword once it has been mapped to the port. Make sure to clear the security ACL with
the include keyword if you make any modifications.
Once authentication is successful, a downloaded ACL is initiated with DHCP snooping, ARP inspection,
or static DHCP bindings. The set of ACEs that were downloaded get recommitted as system-generated
ACLs along with ACLs that were mapped to the port. For example, an ACL that was mapped to a port
and a downloaded ACL are remapped to the port at runtime. The downloaded ACLs are placed in the
include downloaded-acl feature ACE.
The following sections describe how to configure and display information about downloaded ACLs.
Downloadable ACLs can only be mapped to ports with a port-based security ACL mode.
Downloadable ACLs are only supported on switches that feature a Supervisor Engine 720 or
Note
Supervisor Engine 32.
DNS hostnames are supported in the ACEs of downloadable ACLs from RADIUS servers. Make sure to
Note
enable DNS.
If your downloaded ACL is larger than 4 KB, enable IP reassembly by using the set ip reassembly
Note
enable command.
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
15-116
Unrelated configuration information cut out
Unrelated configuration information cut out
Chapter 15
Configuring Access Control
OL-8978-04

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents