EasyManuals Logo

HP PROCURVE 2910AL User Manual

HP PROCURVE 2910AL
594 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #224 background imageLoading...
Page #224 background image
Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
Elements in a RADIUS-assigned ACL Configuration. A RADIUS-
assigned ACL configuration in a RADIUS server has the following elements:
vendor and ACL identifiers:
ProCurve (HP) Vendor-Specific ID: 11
Vendor-Specific Attribute for ACLs: 61 (string = HP-IP-FILTER-RAW)
Setting: HP-IP-FILTER-RAW = < “permit” or “deny” ACE >
(Note that the “string” value and the “Setting” specifier are identical.)
ACL configuration, including:
one or more explicit “permit” and/or “deny” ACEs created by the
system operator
implicit deny any any ACE automatically active after the last operator-
created ACE
Nas-Filter-Rule-Options
Table 6-4. Nas-Filter-Rule Attribute Options
Service Control Method and Operating Notes:
ACLs Applied to Client
Traffic Inbound to the
Switch
Assigns a RADIUS-
configured ACL to
filter inbound packets
received from a
specific client
authenticated on a
switch port.
Standard Attribute: 92
This is the preferred attribute for use in RADIUS-assigned ACLs to configure ACEs to filter IPv4
traffic.
Entry for IPv4-Only ACE To Filter Client Traffic:
Nas-filter-Rule = “< permit or deny ACE >” (Standard Attribute 92)
For example:
Nas-filter-Rule=”permit in tcp from any to any”
ACLs Applied to Client
Traffic Inbound to the
Switch
Assigns a RADIUS-
configured IPv4 ACL
to filter inbound IPv4
packets received from
a specific client
authenticated on a
switch port.
HP-Nas-Filter-Rule (Vendor-Specific Attribute): 61
This attribute is maintained for legacy purposes to support ACEs in RADIUS-assigned ACLs.
However, for new or updated configurations HP recommends using the Standard Attribute (92)
described earlier in this table instead of the HP-Nas-filter-Rule attribute described here.
HP (ProCurve) vendor-specific ID: 11
VSA: 61 (string = HP-Nas-Filter-Rule
Setting: HP-Nas-filter-Rule = “< permit or deny ACE >”
6-18

Table of Contents

Other manuals for HP PROCURVE 2910AL

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP PROCURVE 2910AL and is the answer not in the manual?

HP PROCURVE 2910AL Specifications

General IconGeneral
ModelHP ProCurve 2910al
Switching Capacity128 Gbps
Throughput95.2 Mpps
ManagementWeb, CLI, SNMP
Jumbo Frame SupportYes
ManageableYes
Power100-240 VAC
Power SupplyInternal
Operating Temperature0°C to 45°C (32°F to 113°F)
StackingYes
MAC Address Table Size32000 entries
Routing ProtocolRIP, OSPF
FeaturesIPv6, VLAN, QoS, ACLs
Operating Humidity15% to 95% non-condensing
Uplink Ports4
Power over EthernetYes (PoE+ models available)

Related product manuals