Dynamically Applying Existing ACLs in Flexible Authentication

When a port is authenticated, an IPv4 ACL or IPv6 ACL that exists in the running-config file on the RUCKUS ICX device can be dynamically applied to the port. To do this, you configure the Filter-Id (type 11) attribute on the RADIUS server.

The standard RADIUS Filter-id attribute defined in RFC 2865 for IP ACL is shown in the following table.

Standard RADIUS Attributes for an IP ACL

Attribute Name Attribute ID Data Type Description
Filter-id 11 String IPv4 or IPv6 ACL ID or name as configured on the RUCKUS device

The syntax in the following table is used to configure the Filter-id attribute to refer to an IPv4 or IPv6 ACL.

Syntax for Configuring the Filter-Id Attribute

Syntax

Description

ip.number.in, ip.name.in

Applies the specified numbered or named IPv4 ACL to the authenticated port in the inbound direction.

ip.number.out, ip.name.out

Applies the specified numbered or named IPv4 ACL to the authenticated port in the outbound direction.

ip6.number.in, ip6.name.in

Applies the specified numbered or named IPv6 ACL to the authenticated port in the inbound direction.

ip6.number.out, ip6.name.out

Applies the specified numbered or named IPv6 ACL to the authenticated port in the outbound direction.

The following table lists examples of values that you can assign to the Filter-Id attribute on the RADIUS server to refer to IP ACLs configured on a RUCKUS ICX device.

Sample Filter-Id Attribute Values on the RADIUS Server

Possible Values for the Filter-Id Attribute on the RADIUS Server

ACL Configured on the RUCKUS Device

ip.102.in

ip access-list extended 102

sequence 10 permit ip any any

ip.fdry_filter.in

ip access-list extended fdry_filter

sequence 10 permit icmp any any