HP (Hewlett-Packard) MSM7XX Switch User Manual


 
P
U
B
L
I
C
W
L
A
N
P
U
B
L
I
C
W
L
A
N
P
U
B
L
I
C
W
L
A
N
P
U
B
L
I
C
W
L
A
N
Working with public access attributes
Colubris AV-Pair attribute - Site values
Topology 2:
RADIUS
server
Web/FTP
server
SMTP
server
Network
Operating
Center
20.1
20.2
20.3
20.7
VPN
server
Router/Firewall
20.6
20.5
20.4
Management
station
DNS/DHCP
server
20.1
File
server
Printer
server
Faculty subnet
30.1
30.2
File
server
Printer
server
Student subnet
40.1
40.2
Public Web
server
Registration
Web server
Admin subnet
50.2
50.1
192.168.20.0 192.168.30.0 192.168.40.0 192.168.50.0
192.168.10.0
Building #1
Service controller
10.1
Building #2
Service controller
10.2
Building #3
Service controller
10.3
1.1 1.1 1.1
1.2
192.168.1.0
AP AP
1.3
192.168.1.0
1.2
1.4
1.3
1.5
1.2
192.168.1.0
AP AP
1.3
1.6 1.6
Access list definitions
The RADIUS profile for the service controller contains the following:
access-list=everyone,ACCEPT,tcp,192.168.50.2,80
access-list=students,ACCEPT,tcp,192.168.50.1,80,students_reg,500
access-list=students,ACCEPT,all,192.168.40.0/24,all
access-list=students,DENY,all,192.168.20.0/24,all
access-list=students,DENY,all,192.168.30.0/24,all
access-list=students,ACCEPT,all,all.all,student_internet_use,5000
access-list=faculty,ACCEPT,tcp,192.168.50.1,80,faculty_reg,500
access-list=faculty,ACCEPT,all,192.168.30.0/24,all
access-list=faculty,DENY,all,192.168.20.0/24,all
access-list=faculty,DENY,all,192.168.40.0/24,all
access-list=faculty,ACCEPT,all,all.all,faculty_internet_use,5000
use-access-list=everyone
9-39