
RFC 10065: A YANG Data Model and RADIUS Extension for Policy-Based Network Access Control. This document defines a YANG data model for policy-based network access control, which enables enforcement of network access control policies based on group identity. This YANG data model extends Access Control Lists (ACLs) with date and time parameters to support schedule-aware policy enforcement.
Specifically in scenarios where network access is triggered by user authentication, this document defines a mechanism that eases the maintenance of the mapping between a user group identifier and a set of packet header fields to enforce policy-based network access control. Moreover, this document defines a Remote Authentication Dial-in User Service (RADIUS) attribute that is used to communicate the user group identifier as part of identification and authorization information..
RFC Editor
این سند یک مدل دادهی یانگ را برای کنترل دسترسی شبکه مبتنی بر سیاست تعریف میکند، که امکان اجرای سیاستهای کنترل دسترسی شبکه را بر اساس هویت گروه فراهم میسازد. این مدل دادهی یانگ، لیستهای کنترل دسترسی (ACL) را با پارامترهای تاریخ و زمان گسترش میدهد تا از اجرای سیاستهای آگاه از زمان پشتیبانی کند.
به طور خاص، در سناریوهایی که دسترسی به شبکه توسط احراز هویت کاربر آغاز میشود، این سند یک مکانیزم را تعریف میکند که نگهداری ارتباط بین یک شناسه گروه کاربر و مجموعهای از فیلدهای هدر بسته را برای اجرای کنترل دسترسی شبکه مبتنی بر سیاست آسانتر میکند. علاوه بر این، این سند یک ویژگی سرویس احراز هویت از راه دور (RADIUS) را تعریف میکند که برای انتقال شناسه گروه کاربر به عنوان بخشی از اطلاعات شناسایی و مجوز استفاده میشود.