Configuring An Acl In A Radius Server - ProCurve 2610 Manual

2610 / 2610-pwr series
Hello, I am your AI assistant. How can I help you?
Table of Contents

Advertisement

tication is through MAC Authentication, then the client MAC address
forms the credential set.) For more on this topic, refer to "Configuring
an ACL in a RADIUS Server" on page 6-15.
Multiple Clients Using the Same Username/Password Pair:
Multiple clients using the same username/password pair will use
duplicate instances of the same ACL.
Limits for ACEs in Dynamic Port ACLs: The switch supports up
to 80 characters in a single ACE. Exceeding this limit causes the
related client authentication to fail.
Effect of Dynamic Port ACLs on Inbound Traffic for Two
Clients on the Same Port: On a port configured for 802.1X user-
based access where up to two clients are connected, if a given client's
authentication results in a dynamic port ACL assignment, then the
authentication of the other client concurrently using the port must
also include a dynamic port ACL assignment. Thus, if a RADIUS server
is configured to assign a dynamic port ACL when client "X" authenti­
cates, but is not configured to do the same for client "Y", then traffic
from client "Y" will be blocked whenever client "X" is authenticated
on the port (and client "Y" will be deauthenticated). For this reason,
if two clients are authenticated on a port, a separate dynamic port
ACL must be assigned by a RADIUS server for each authenticated
client. Inbound IP traffic from a client whose authentication does not
result in a dynamic port ACL assignment will be blocked and the client
will be deauthenticated. Also, if 802.1X port-based access is config­
ured on the port, only one client can be authenticated on the port at
any given time. In this case, no other inbound client traffic is allowed.

Configuring an ACL in a RADIUS Server

This section provides general guidelines for configuring a RADIUS server to
specify dynamic port ACLs. Also included is an example configuration for a
FreeRADIUS server application. However, to configure support for these
services on a specific RADIUS server application, please refer to the docu­
mentation provided with the application.
Elements in a Dynamic Port ACL Configuration. A dynamic port ACL
configuration in a RADIUS server has the following elements:
vendor and ACL identifiers:
ProCurve (HP) Vendor-Specific ID: 11
Vendor-Specific Attribute for ACLs: 61 (string = HP-IP-FILTER-RAW)
Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
6-15

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the 2610 and is the answer not in the manual?

Questions and answers

Table of Contents