Overview Of Radius-Assigned, Dynamic Port Acls - ProCurve 2610 Manual

2610 / 2610-pwr series
Table of Contents

Advertisement

Note

Overview of RADIUS-Assigned, Dynamic Port ACLs

Dynamic port ACLs enhance network and switch management access security
and traffic control by permitting or denying authenticated client access to
specific network resources and to the switch management interface. This
includes preventing clients from using TCP or UDP applications (such as
Telnet, SSH, Web browser, and SNMP) if you do not want their access
privileges to include these capabilities.
This feature is designed for use on the network edge to accept RADIUS-
assigned, per-port ACLs (dynamic port ACLs) for Layer-3 filtering of IP traffic
entering the switch from authenticated clients. A given dynamic port ACL is
identified by a unique username/password pair or client MAC address, and
applies only to IP traffic entering the switch from clients that authenticate
with the unique credentials. The switch allows multiple dynamic port ACLs
on a given port, up to the maximum number of authenticated clients allowed
on the port.
A dynamic port ACL filters IP traffic entering the switch from the client whose
authentication initiated the ACL assignment. Filtering criteria is based on
destination and/or IP traffic type (such as TCP and UDP traffic) and traffic
counter options. Implementing the feature requires:
RADIUS authentication using the 802.1X, Web authentication, or MAC
authentication services available on the switch to provide client
authentication services
configuring the ACLs on the RADIUS server (instead of the switch),
and assigning each ACL to the username/password pair or MAC
address of the clients you want the ACLs to support
Using RADIUS to dynamically apply per-port ACLs to edge ports enables the
switch to filter IP traffic coming from outside the network, thus removing
unwanted IP traffic as soon as possible and helping to improve system
performance.
A dynamic port ACL assignment filters all inbound IP traffic from an authen­
ticated client on a port, regardless of whether the client's IP traffic is to be
switched or routed.
Dynamic port ACLs can be used either with or without PCM and IDM support.
(Refer to "Optional PCM and IDM Applications" on page 6-2.)
Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
6-9

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the 2610 and is the answer not in the manual?

Questions and answers

Table of Contents