Configuring A Downloaded Acl For Dot1X For An Ip Phone - Cisco WS-C6506 Software Manual

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Chapter 15
Configuring Access Control

Configuring a Downloaded ACL for Dot1x for an IP Phone

To configure a downloaded ACL for dot1x with an IP phone, perform these steps:
Grant permission for the IP phone by configuring the base-ACL.
Step 1
Console> (enable) set security acl ip dacl1x permit arp-inspection any any
OL-8978-04
7. deny ip host 9.6.6.104 67.104.129.189 255.255.0.0
8. include downloaded-acl dot1x
Displays the dot1x user all O/P:
Console> (enable) show dot1x user all
Username
----------------------
host
Downloaded ACL
---------------------------------------------------------
ACSACL#-IP-test-44bb6f49
Derived ACL
--------------------------------
dacl1x_5_35
Checks the DACL name:
Console> (enable) show security acl downloaded-acl all
Downloaded ACL Summary:
ACL Name
-----------------------------------------------------------------------
1.#ACSACL#-IP-test-44bb6f49
Displays the user-mapped IP, port, and the feature:
Console> (enable) show security acl downloaded-acl user-map
Downloaded ACL User Map:
ACL Name : #ACSACL#-IP-test-44bb6f49
User Count : 1
Num of Aces : 5
Ip Address
------------------------------------------------------------
1. 9.6.6.104
Displays the DACL information specific to the port:
Console> (enable) show security acl downloaded-acl port 5/35
Port
IP Address
----- ---------------- ---------- -------------------------------------
5/35 9.6.6.104
Displays the ACEs that were downloaded from the RADIUS server:
Console (enable) show security acl downloaded-acl #ACSACL#-IP-test-44bb6f49
Downloaded ACE's for #ACSACL#-IP-test-44bb6f49:
permit ip any 10.76.255.85 255.255.255.0
deny ip any 64.104.129.189 255.255.0.0
permit tcp any eq 21 host 10.76.255.25
deny ip any 6.104.129.189 255.255.0.0
deny ip any 67.104.129.189 255.255.0.0
Mod/Port
--------
5/35
Date/Time
Fri Jul 21 2006, 05:05:58
mNo/pNo
5/35
Feature
Downloaded ACL
dot1x
#ACSACL#-IP-test-44bb6f49
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
UserIP
VLAN
------
------
9.6.6.104
16
Feature
dot1x
Downloadable ACLs
15-119

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents