When a port is authenticated, an IPv4 ACL or IPv6 ACL that exists in the running-config
file on the
RUCKUS ICX device can be dynamically applied to the port. To do this, you configure the
Filter-Id (type 11) attribute on the RADIUS server.
The syntax in the following table is used to configure the Filter-Id attribute to
refer to an IP ACL.
Syntax for Configuring the Filter-Id Attribute
|
Syntax
|
Description
|
|
ip.number.in,
ip.name.in
|
Applies the specified numbered or named IPv4 ACL to the authenticated port in the
inbound direction.
|
|
ip.number.out,
ip.name.out
|
Applies the specified numbered or named IPv4 ACL to the authenticated port in the
outbound direction.
|
|
ip6.number.in,
ip6.name.in
|
Applies the specified numbered or named IPv6 ACL to the authenticated port in the
inbound direction.
|
|
ip6.number.out,
ip6.name.out
|
Applies the specified numbered or named IPv6 ACL to the authenticated port in the
outbound direction.
|
The following table lists examples of values that you can assign to the Filter-Id
attribute on the RADIUS server to refer to IP ACLs configured on a
RUCKUS ICX device.
Sample Filter-Id Attribute Values on the RADIUS Server
|
Possible Values for the Filter-Id Attribute on the RADIUS Server
|
ACL Configured on the
RUCKUS Device
|
|
ip.102.in
|
ip access-list extended 102 deny ip any
10.1.0.0 0.0.0.255
ip access-list extended access-list 102 permit
ip any any
|
|
ip.fdry_filter.in
|
ip access-list extended fdry_filter
deny ip any 10.1.0.0 0.0.0.255
permit ip any any
|