Dynamically Applying Existing ACLs in Flexible Authentication
When a port is authenticated, an IPv4 ACL or IPv6 ACL that exists in the running-config file on the RUCKUS ICX device can be dynamically applied to the port. To do this, you configure the Filter-Id (type 11) attribute on the RADIUS server.
The standard RADIUS Filter-id attribute defined in RFC 2865 for IP ACL is shown in the following table.
Standard RADIUS Attributes for an IP ACL
| Attribute Name | Attribute ID | Data Type | Description |
|---|---|---|---|
| Filter-id | 11 | String | IPv4 or IPv6 ACL ID or name as configured on the RUCKUS device |
The syntax in the following table is used to configure the Filter-id attribute to refer to an IPv4 or IPv6 ACL.
Syntax for Configuring the Filter-Id Attribute
The following table lists examples of values that you can assign to the Filter-Id attribute on the RADIUS server to refer to IP ACLs configured on a RUCKUS ICX device.