Access Security Guide K/KA/KB.15.15

permit: any forwarding, 318
planning; ACL, IPv4:policies, 316
planning;ACL, IPv4:configuration planning, 313
policy application points, 302
policy type, 328
port ACL operation defined, 307
port;ACL, IPv4:trunk;ACL, IPv4:port added to trunk;ACL,
IPv4:port removed from trunk;trunk:port added or
removed, ACL, 321
ports affected, 322
precedence, 274
precedence, numbers and names, 266
precedence;ACL, IPv4:ToS: setting, 313
purpose, 302
RACL:defined;RACL defined, 305
RACL:operation defined, 306
RACL:RACL applications, 307
RACL:screening switched traffic, 311
RADIUS server support, 211
RADIUS-assigned, 305
RADIUS-assigned ACL operation defined, 307
RADIUS-assigned ACL, IPv4:multiple clients
connected;ACL, IPv4:RADIUS-assigned ACL,
IPv4:denied traffic, 309
RADIUS-assigned, implicit deny, 218
RADIUS-assigned, limit, 225
RADIUS-assigned;, 305
RADIUS-assigned;ACL, IPv4:RADIUS-assigned, IPv4 and
IPv6;, 308, 310
remark:remove from an ACE, 293
replacing, 321
resequence, 271
routing requirement, 320
rules: configuration;ACL, IPv4:rules:operation, 320
SA or DA on the switch;ACL, IPv4:traffic: to/from the
switch, 322
scalability, 225
security use, 302, 317
security use: caution, 318
sequence number, 320
sequence number: interval, 271
sequence number:out-of-range, 288
sequence number:use to delete ACE, 289
source routing, caution;source-routing,
caution;routing:source-routing, caution, 314, 327
standard:configure, 318
standard:example;, 262
standard:named, configure, 259
standard:numbered, configure, 261
standard:numeric I.D. range, 327
standard:structure, 328
standard:use, 305, 318
static port ACL: application;ACL, IPv4:RADIUS-assigned
ACL application, 308
static VLAN requirement, 322
static VLAN requirement;ACL, IPv4:VLANs , 321
static, defined;static ACL, 305
statistics counters: RACL counter operation, 299
supernetting; supernetting, 323
switched packets , 322
Syslog, 312
TCP control bits, 263, 267, 327
TCP control bits;ACL, IPv4:control bits, TCP;TCP control
bits;control bits, TCP, 268
TCP or UDP port number, IANA;IANA, 268
TCP/UDP operators , 267
TCP/UDP, port names, 268
ToS: numbers and names, 266
traffic types filtered, 317
traffic: types filtered, 302
troubleshooting, 295
troubleshooting client authentication, 219
trunk: adding port;, 321
type, 277, 288, 318, 330
user-based security;ACL, IPv4:port-based security, 309
VACL, 305
VACL:operation defined, 306
VACL:VACL applications, 308
VLAN ACL, IPv4, 305
where applied to traffic;ACL, IPv4:routed traffic, 322
wildcard, 324
ACL, IPv6
display:assignments, 278
display:content of an ACL, 278
dual stack;ACL, IPv4:dual stack, 310
hit count, 333
implicit IPv6 deny, IPv4-only rule, 217
IPv6 traffic implicitly denied, 217
limit, 225
limit;ACL, IPv6:RADIUS-assigned, limit;ACL,
IPv4:limit;ACL, IPv4:RADIUS-assigned, limit;ACL,
IPv4:scalability;ACL, IPv6:scalability, 331
loggong:timer;ACL, IPv6:logging:timer, 275
RADIUS server support, 211
RADIUS-assigned ACL, 308
RADIUS-assigned, implicit deny, 218
RADIUS-assigned, limit, 225
scalability, 225
statistics counters, ACE, IPv4;ACL, IPv6:monitoring;ACL,
IPv4 statistics counters, ACE;ACL, IPv4:monitoring,
295
troubleshooting client authentication, 219
type, 278, 279
user-based security;ACL, IPv6:port-based security, 310
address
authorized for port security, 398
applying
connection-rate ACLs, 58, 62, 67
authentication
DCA-applied parameters to non-authenticated client
sessions, 438
MAC, 72
NIM override, 438
RADIUS override, 200, 439
RADIUS server groups, 174
web-based, 72
authentication session
client-specific configuration applied with DCA, 438
526 Index