RFC 10065: Ein YANG-Datenmodell und eine RADIUS-Erweiterung für die policybasierte Netzwerkzugriffskontrolle

07/10/2026 às 00:0078 Aufrufe
RFC 10065: A YANG Data Model and RADIUS Extension for Policy-Based Network Access Control. This document defines a YANG data model for policy-based network access control, which enables enforcement of network access control policies based on group identity. This YANG data model extends Access Control Lists (ACLs) with date and time parameters to support schedule-aware policy enforcement.

Specifically in scenarios where network access is triggered by user authentication, this document defines a mechanism that eases the maintenance of the mapping between a user group identifier and a set of packet header fields to enforce policy-based network access control. Moreover, this document defines a Remote Authentication Dial-in User Service (RADIUS) attribute that is used to communicate the user group identifier as part of identification and authorization information..
RFC 10065: A YANG Data Model and RADIUS Extension for Policy-Based Network Access Control. This document defines a YANG data model for policy-based network access control, which enables enforcement of network access control policies based on group identity. This YANG data model extends Access Control Lists (ACLs) with date and time parameters to support schedule-aware policy enforcement. Specifically in scenarios where network access is triggered by user authentication, this document defines a mechanism that eases the maintenance of the mapping between a user group identifier and a set of packet header fields to enforce policy-based network access control. Moreover, this document defines a Remote Authentication Dial-in User Service (RADIUS) attribute that is used to communicate the user group identifier as part of identification and authorization information..
RFC Editor

Dieses Dokument definiert ein YANG-Datenmodell für die policybasierte Netzwerkkontrolle, das die Durchsetzung von Netzwerkkontrollrichtlinien auf der Grundlage der Gruppenerkennung ermöglicht. Dieses YANG-Datenmodell erweitert Access Control Lists (ACLs) um Datums- und Zeitparameter, um die Durchsetzung von Richtlinien zu unterstützen, die auf Zeitpläne basieren.

Insbesondere in Szenarien, in denen der Netzwerkzugriff durch die Benutzerauthentifizierung ausgelöst wird, definiert dieses Dokument einen Mechanismus, der die Pflege der Zuordnung zwischen einem Gruppenerkennungs- und einem Satz von Paketheaderfeldern zur Durchsetzung der policybasierten Netzwerkkontrolle erleichtert. Darüber hinaus definiert dieses Dokument ein Remote Authentication Dial-in User Service (RADIUS)-Attribut, das zur Übermittlung des Gruppenerkennungs-Identifikators als Teil der Identifizierungs- und Autorisierungsinformationen verwendet wird.

Quelle
RFC Editor
Original öffnen ↗

⚙Automatisch übersetzt.

War diese Nachricht nützlich?

Debatten 0

Seien Sie der Erste, der zur Debatte beiträgt.

Teilen Sie Ihre Informationen und fördern Sie Ihr Argument

Zögern Sie nicht, nützliche Informationen zu veröffentlichen.

Um an der Diskussion teilzunehmen, melden Sie sich an oder erstellen Sie ein kostenloses Konto.