RFC 10065: Modello di dati YANG e estensione RADIUS per il controllo dell'accesso alla rete basato su policy

07/10/2026 às 00:0074 visualizzazioni
RFC 10065: A YANG Data Model and RADIUS Extension for Policy-Based Network Access Control. This document defines a YANG data model for policy-based network access control, which enables enforcement of network access control policies based on group identity. This YANG data model extends Access Control Lists (ACLs) with date and time parameters to support schedule-aware policy enforcement.

Specifically in scenarios where network access is triggered by user authentication, this document defines a mechanism that eases the maintenance of the mapping between a user group identifier and a set of packet header fields to enforce policy-based network access control. Moreover, this document defines a Remote Authentication Dial-in User Service (RADIUS) attribute that is used to communicate the user group identifier as part of identification and authorization information..
RFC 10065: A YANG Data Model and RADIUS Extension for Policy-Based Network Access Control. This document defines a YANG data model for policy-based network access control, which enables enforcement of network access control policies based on group identity. This YANG data model extends Access Control Lists (ACLs) with date and time parameters to support schedule-aware policy enforcement. Specifically in scenarios where network access is triggered by user authentication, this document defines a mechanism that eases the maintenance of the mapping between a user group identifier and a set of packet header fields to enforce policy-based network access control. Moreover, this document defines a Remote Authentication Dial-in User Service (RADIUS) attribute that is used to communicate the user group identifier as part of identification and authorization information..
RFC Editor

Questo documento definisce un modello di dati YANG per il controllo dell'accesso alla rete basato su policy, che consente di applicare policy di controllo dell'accesso alla rete in base all'identità del gruppo. Questo modello di dati YANG estende le Access Control Lists (ACL) con parametri di data e ora per supportare l'applicazione di policy basata su orari.

In particolare, in scenari in cui l'accesso alla rete è innescato dall'autenticazione dell'utente, questo documento definisce un meccanismo che facilita la manutenzione della mappatura tra un identificatore di gruppo utente e un insieme di campi di intestazione di pacchetto per l'applicazione del controllo dell'accesso alla rete basato su policy. Inoltre, questo documento definisce un attributo di Remote Authentication Dial-in User Service (RADIUS) che viene utilizzato per comunicare l'identificatore del gruppo utente come parte delle informazioni di identificazione e autorizzazione.

Fonte
RFC Editor
Apri l'originale ↗

⚙Tradotto automaticamente.

Questa notizia è stata utile?

Dibattiti 0

Sii il primo a contribuire al dibattito.

Condividi le tue informazioni e promuovi il tuo argomento

Non esitare a pubblicare informazioni o dati che possano essere utili.

Per partecipare al dibattito, accedi o crea un account gratuito.