RFC 10065: یک مدل داده YANG و افزونه RADIUS برای کنترل دسترسی شبکه مبتنی بر سیاست

07/10/2026 às 00:0080 بازدید
RFC 10065: A YANG Data Model and RADIUS Extension for Policy-Based Network Access Control. This document defines a YANG data model for policy-based network access control, which enables enforcement of network access control policies based on group identity. This YANG data model extends Access Control Lists (ACLs) with date and time parameters to support schedule-aware policy enforcement.

Specifically in scenarios where network access is triggered by user authentication, this document defines a mechanism that eases the maintenance of the mapping between a user group identifier and a set of packet header fields to enforce policy-based network access control. Moreover, this document defines a Remote Authentication Dial-in User Service (RADIUS) attribute that is used to communicate the user group identifier as part of identification and authorization information..
RFC 10065: A YANG Data Model and RADIUS Extension for Policy-Based Network Access Control. This document defines a YANG data model for policy-based network access control, which enables enforcement of network access control policies based on group identity. This YANG data model extends Access Control Lists (ACLs) with date and time parameters to support schedule-aware policy enforcement. Specifically in scenarios where network access is triggered by user authentication, this document defines a mechanism that eases the maintenance of the mapping between a user group identifier and a set of packet header fields to enforce policy-based network access control. Moreover, this document defines a Remote Authentication Dial-in User Service (RADIUS) attribute that is used to communicate the user group identifier as part of identification and authorization information..
RFC Editor

این سند یک مدل داده‌ی یانگ را برای کنترل دسترسی شبکه مبتنی بر سیاست تعریف می‌کند، که امکان اجرای سیاست‌های کنترل دسترسی شبکه را بر اساس هویت گروه فراهم می‌سازد. این مدل داده‌ی یانگ، لیست‌های کنترل دسترسی (ACL) را با پارامترهای تاریخ و زمان گسترش می‌دهد تا از اجرای سیاست‌های آگاه از زمان پشتیبانی کند.

به طور خاص، در سناریوهایی که دسترسی به شبکه توسط احراز هویت کاربر آغاز می‌شود، این سند یک مکانیزم را تعریف می‌کند که نگهداری ارتباط بین یک شناسه گروه کاربر و مجموعه‌ای از فیلدهای هدر بسته را برای اجرای کنترل دسترسی شبکه مبتنی بر سیاست آسان‌تر می‌کند. علاوه بر این، این سند یک ویژگی سرویس احراز هویت از راه دور (RADIUS) را تعریف می‌کند که برای انتقال شناسه گروه کاربر به عنوان بخشی از اطلاعات شناسایی و مجوز استفاده می‌شود.

⚙محتوا به‌صورت خودکار ماشینی ترجمه شده است.

این خبر مفید بود؟

بحث‌ها 0

نخستین مشارکت‌کننده در بحث باشید.

اطلاعات خود را به اشتراک بگذارید و استدلال خود را مطرح کنید

در انتشار اطلاعات یا داده‌های مفید تردید نکنید.

برای شرکت در بحث، وارد شوید یا حساب رایگان بسازید.