HP (Hewlett-Packard) MSM7XX Switch User Manual


 
Working with public access attributes
Colubris AV-Pair attribute - Site values
The following diagram illustrates how incoming traffic from a user session is processed by
the access list mechanism.
Incoming user traffic
Service Controller Access List
DENY
NO MATCH ACCEPT
User Access List
DENY
NO MATCH ACCEPT
Authenticated and
a user access
list exists
Authenticated and
no user access list
exists
Unauthenticated
To protected network
Dropped
via the Internet port
Within each access list, traffic cascades through the list rules in a similar manner.
Incoming traffic
Rule 3
DENY
NO MATCH ACCEPT
DENY
NO MATCH ACCEPT
DENY
NO MATCH ACCEPT
DENY
NO MATCH ACCEPT
Rule 2
Rule 1
Access list rules are numbered according to the order in which they are specified. Only data
that is not accepted or denied by a rule is available to the next rule in the list.
9-32