发明授权
- 专利标题: Method and apparatus for retrieving access control information
- 专利标题(中): 用于检索访问控制信息的方法和装置
-
申请号: US10310572申请日: 2002-12-04
-
公开(公告)号: US07225263B1公开(公告)日: 2007-05-29
- 发明人: Andrew M. Clymer , Darran Potter
- 申请人: Andrew M. Clymer , Darran Potter
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Hickman Palermo Truong & Becker LLP
- 主分类号: G06F15/16
- IPC分类号: G06F15/16
摘要:
A method is disclosed for creating and storing troubleshooting information for providing access control information to a network device. A provisioning of one or more access control lists, and one or more associations of the access control lists to users of the network device, are received. As part of authenticating a user login request, a name of a first access control list is provided to the network device, selected from among the one or more access control lists that based on the associations. A request is received from the network device for a first access control list that is associated with a user of the network device. The request includes the name of the access control list. The first access control list is sent to the network device in response to the request. Embodiments may use RADIUS packets for communicating ACLs from an authentication server to a firewall, and a de-fragmentation approach is disclosed for downloading ACLs that exceed the maximum RADIUS packet size. Further, using an ACL renaming approach the firewall is forced to update its cache when a user subsequently logs in and the corresponding ACL has changed in the interim.
信息查询