Colubris Networks CN3000 Administrator's Manual page 157

Table of Contents

Advertisement

Chapter 7 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Customizing CN3000 and customer settings - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 7
Network
Operating
Router/Firewall
Center
20.7
SMTP
server
20.3
Web/FTP
server
20.2
RADIUS
server
20.1
192.168.20.0
192.168.10.0
Building #1
CN3000
10.1
1.1
192.168.1.0
1.2
CN300
CN300
The RADIUS profile for the CN3000 contains:
access-list=everyone,ACCEPT,tcp,192.168.50.2,80
access-list=students,ACCEPT,tcp,192.168.50.1,80,students_reg,500
access-list=students,ACCEPT,all,192.168.40.0/24,all
access-list=students,DENY,all,192.168.20.0/24,all
access-list=students,DENY,all,192.168.30.0/24,all
access-list=students,ACCEPT,all,all.all,student_internet_use,5000
access-list=faculty,ACCEPT,tcp,192.168.50.1,80,faculty_reg,500
access-list=faculty,ACCEPT,all,192.168.30.0/24,all
access-list=faculty,DENY,all,192.168.20.0/24,all
access-list=faculty,DENY,all,192.168.40.0/24,all
access-list=faculty,ACCEPT,all,all.all,faculty_internet_use,5000
use-access-list=everyone
The RADIUS profile for the students contains:
use-access-list=students
The RADIUS profile for the faculty contains:
use-access-list=faculty
This definition creates three access lists: everyone, students, and faculty.
Everyone
This list applies to all users (students, teachers, guests), whether they are authenticated
or not. This is because the list is active on the CN3000, which is accomplished with the
entry:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 157 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
DNS/DHCP
server
20.6
Management
station
20.5
VPN
server
20.4
Building #2
192.168.1.0
1.2
1.3
1.4
1.6
Faculty subnet
Student subnet
File
server
30.2
40.2
Printer
server
20.1
30.1
40.1
192.168.30.0
192.168.40.0
CN3000
10.2
1.1
1.3
1.5
1.6
Admin subnet
File
Public Web
server
server
50.2
Printer
Registration
server
Web server
50.1
192.168.50.0
Building #3
CN3000
10.3
1.1
192.168.1.0
1.2
CN300
CN300
1.3

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents