ProCurve 6200yl User's Guide Page 235

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 234
7-29
Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
Causes of Client Deauthentication Immediately
After Authenticating
ACE formatted incorrectly in the RADIUS server
“from”, “any”, or “to” keyword missing
An IP protocol number in the ACE exceeds 255.
An optional UDP or TCP port number is invalid, or a UDP/TCP port
number is specified when the protocol is neither UDP or TCP.
A dynamic port ACL limit has been exceeded.
An ACE in the ACL for a given authenticated client exceeds 80
characters.
The TCP/UDP port-range quantity of 14 per slot or port group has been
exceeded.
The rule limit of 3048 per slot or port group has been exceeded.
Monitoring Shared Resources
Currently active, RADIUS-based authentication sessions (including ProCurve
IDM client sessions) using dynamic port ACLs share internal routing switch
resources with several other features. The routing switch provides ample
resources for all features. However, if the internal resources do become fully
ACE parsing error, destination IP,
< ace-# > client < mac-address > port
< port-# >.
Notifies of a problem with the destination IP field in the
indicated ACE of the access list for the indicated client on
the indicated switch port.
ACE parsing error, tcp/udp ports,
< ace-# > client < mac-address > port
< port-# >.
Notifies of a problem with the TCP/UDP port field in the
indicated ACE of the access list for the indicated client on
the indicated switch port.
Rule limit per ACL exceeded. < ace-# >
client < mac-address > port < port-# >.
Notifies that an ACL has too many rules.
Duplicate mac. An ACl exists for
client. Deauthenticating second.
client < mac-address > port < port-# >.
Notifies that an ACL for this mac on this port already exists.
Invalid Access-list entry length,
client < mac-address > port < port-# >.
Notifies that the string configured for an ACE entry on the
Radius server exceeds 80 characters.
Memory allocation failure for IDM
ACL.
Notifies of a memory allocation failure for a dynamic port
ACL assigned by a RADIUS server performing client
authentication. (This message is used in IDM and non-IDM
environments.)
Message Meaning
Page view 234
1 2 ... 230 231 232 233 234 235 236 237 238 239 240 ... 595 596

Comments to this Manuals

No comments