ProCurve 6200yl User's Guide Page 219

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 218
7-13
Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
Contrasting Dynamic and Static ACLs
Table 7-1, below, highlights several key differences between the static ACLs
configurable on switch VLANs and ports, and the dynamic port ACLs that can
be assigned to individual ports by a RADIUS server.
Table 7-1. Contrasting Dynamic and Static ACLs
Dynamic Port ACLs Static Port and VLAN ACLs
Configured in client accounts on a RADIUS server. Configured on switch ports and VLANs.
Designed for use on the edge of the network where filtering
of IP traffic entering the switch from individual,
authenticated clients is most important and where clients
with differing access requirements are likely to use the
same port.
Designed for use where the filtering needs focus on static
configurations covering:
selected routed IP traffic (RACLs)
switched or routed IP traffic entering the switch from
multiple sources or from unauthenticated sources
IP traffic from multiple sources and having a destination
on the switch itself
Implementation requires client authentication. Client authentication not a factor.
Identified by the credentials (username/password pair or
the MAC address) of the specific client the ACL is intended
to service.
Identified by a number in the range of 1-199 or an
alphanumeric name.
Supports dynamic assignment to filter only the IP traffic
entering the switch from an authenticated client on the port
to which the client is connected. (IP traffic can be routed or
switched, and includes IP traffic having a DA on the switch
itself.)
Supports static assignments to filter switched or routed IP
traffic entering the switch, or routed IP traffic leaving the
switch.
When the authenticated client session ends, the switch
removes the RADIUS-assigned (dynamic port) ACL from the
client port.
Remains statically assigned to the port or VLAN.
Allows one RADIUS-assigned (dynamic port) ACL per
authenticated client on a port. (Each such ACL filters traffic
from a different, authenticated client.)
Note: The switch provides ample resources for supporting
RADIUS-assigned ACLs and other features. However, the
actual number of ACLs supported depends on the switch’s
current feature configuration and the related resource
requirements. For more information, refer to the appendix
titled “Monitoring Resources” in the Management and
Configuration Guide for your switch.
Supports one each of the following:
inbound RACL
outbound RACL
•VACL
static port ACL
Supports only extended ACLs. (Refer to Terminology.) Supports standard, extended, and connection-rate ACLs.
(Refer to “Configuring and Applying Connection-Rate ACLs”
on page 3-19.)
Page view 218
1 2 ... 214 215 216 217 218 219 220 221 222 223 224 ... 595 596

Comments to this Manuals

No comments