Working with RADIUS attributes
Colubris AV-Pair - Site attribute values
15-42
Topology 2:
Access list definitions
The RADIUS profile for the controller contains the following:
access-list=everyone,ACCEPT,tcp,192.168.50.2,80
access-list=students,ACCEPT,tcp,192.168.50.1,80,students_reg,500
access-list=students,ACCEPT,all,192.168.40.0/24,all
access-list=students,DENY,all,192.168.20.0/24,all
access-list=students,DENY,all,192.168.30.0/24,all
access-list=students,ACCEPT,all,all.all,student_internet_use,5000
access-list=faculty,ACCEPT,tcp,192.168.50.1,80,faculty_reg,500
access-list=faculty,ACCEPT,all,192.168.30.0/24,all
access-list=faculty,DENY,all,192.168.20.0/24,all
access-list=faculty,DENY,all,192.168.40.0/24,all
access-list=faculty,ACCEPT,all,all.all,faculty_internet_use,5000
use-access-list=everyone
VPN
server
Router/Firewall
192.168.30.0
192.168.10.0
192.168.1.0 192.168.1.0192.168.1.0
10.1
1.1 1.1 1.1
1.2
1.4
1.6
1.3
1.5
1.6
10.2 10.3
192.168.20.0
20.1
20.2
20.3 20.6
20.7
20.1
20.5
20.4
192.168.40.0 192.168.50.0
RADIUS
server
Web/FTP
server
SMTP
server
File
server
File
server
Public Web
server
Registration
Web server
Printer
server
Printer
server
Management
station
DNS/DHCP
server
Network
Operating
Center
Building #1 Building #2 Building #3
Faculty subnet Student subnet Admin subnet
30.1 40.1
30.2 40.2 50.2
50.1
AP AP
1.2 1.3
AP AP
1.2 1.3
Service controller Service controller Service controller
P
U
B
L
I
C
W
L
A
N
P
U
B
L
I
C
W
L
A
N
P
U
B
L
I
C
W
L
A
N
P
U
B
L
I
C
W
L
A
N