ProCurve 6200yl User's Guide Page 214

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 213
7-8
Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
Configuring and Using
RADIUS-Assigned Access Control Lists
Introduction
A RADIUS-assigned ACL is a dynamic port ACL configured on a RADIUS
server and assigned by the server to filter traffic entering the switch through
a specific port from an authenticated client. Note that client authentication
can be enhanced by using ProCurve Manager with the optional IDM applica-
tion. (Refer to “Optional PCM and IDM Applications” on page 7-2.)
The information in this section describes how to apply RADIUS-assigned,
dynamic port ACLs on the switch, and assumes a general understanding of
ACL structure and operation. If you need information on ACL filtering criteria,
design, and operation, please refer to the chapter 10, “Access Control Lists
(ACLs)”.
Terminology
ACE: See Access Control Entry, below.
Access Control Entry (ACE): An ACE is a policy consisting of a packet-
handling action and criteria to define the packets on which to apply the
action. For dynamic port ACLs, the elements composing the ACE include:
permit or drop (action)
•in < ip-packet-type > from any (source)
to < ip-address [/ mask ] | any > (destination)
[ port-# ] (optional TCP or UDP application port numbers used when
the packet type is TCP or UDP)
ACL: See Access Control List, below.
Access Control List (ACL): A list (or set) consisting of one or more
explicitly configured Access Control Entries (ACEs) and terminating with
an implicit “deny” default which drops any IP packets that do not have a
match with any explicit ACE in the named ACL. An ACL can be “standard”
or “extended”. See “Standard ACL” and “Extended ACL”. Both can be
applied in any of the following ways:
Page view 213
1 2 ... 209 210 211 212 213 214 215 216 217 218 219 ... 595 596

Comments to this Manuals

No comments