IPv4 Access Control Lists (ACLs)

Overview

Static Port ACL and Dynamic Port ACL Applications

An IPv4 static port ACL filters any IPv4 traffic inbound on the designated port, regardless of whether the traffic is switched or routed.

Dynamic (RADIUS-assigned) Port ACL Applications

Dynamic (RADIUS-assigned) port ACLs are configured on RADIUS servers and, where such servers support configuration for IPv4 traffic filtering, can be assigned to filter IPv4 traffic inbound from clients authenticated by such servers. For example, client “A” connects to a given port and is authenticated by a RADIUS server. Because the server is configured to assign a dynamic ACL to the port, the IPv4 traffic inbound on the port from client “A” is filtered.

Effect of Dynamic Port ACLs When Multiple Clients Are Using the

Same Port. Some network configurations may allow multiple clients to authenticate through a single port where a RADIUS server assigns a separate, dynamic port ACL in response to each client’s authentication on that port. In such cases, a given client’s inbound traffic will be allowed only if the RADIUS authentication response for that client includes a dynamic port ACL. For example, in figure 9-1(below), clients A through D authenticate through the same port (B1) on the ProCurve-A switch.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

ProCurve-A

 

 

 

 

 

 

 

 

 

RADIUS

 

 

 

 

 

 

 

 

 

 

Port B1

 

 

 

 

 

 

 

 

 

 

10.100.0.0

 

 

 

Server

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

LAN

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Unmanaged

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Switch

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Client A

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Client D

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Client B

 

 

 

 

Client C

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Figure 9-1. Example of Multiple Clients Authenticating Through a Single Port

In this case, the RADIUS server must be configured to assign a dynamic port ACL to port B1 each time any of the clients authenticates on the port.

9-15