4-15
Web and MAC Authentication
Setup Procedure for Web/MAC Authentication
Configuring the RADIUS Server To Support MAC
Authentication
On the RADIUS server, configure the client device authentication in the same
way that you would any other client, except:
■
Configure the client device’s (hexadecimal) MAC address as both
username and password. Be careful to configure the switch to use the
same format that the RADIUS server uses. Otherwise, the server will
deny access. The switch provides four format options:
aabbccddeeff
(the default format)
aabbcc-ddeeff
aa-bb-cc-dd-ee-ff
aa:bb:cc:dd:ee:ff
AABBCCDDEEFF
AABBCC-DDEEFF
AA-BB-CC-DD-EE-FF
AA:BB:CC:DD:EE:FF
■
If the device is a switch or other VLAN-capable device, use the base
MAC address assigned to the device, and not the MAC address
assigned to the VLAN through which the device communicates with
the authenticator switch. Note that the switch applies a single MAC
address to all VLANs configured in the switch. Thus, for a given
switch, the MAC address is the same for all VLANs configured on the
switch. (Refer to the chapter titled “Static Virtual LANs (VLANs)” in
the
Advanced Traffic Management Guide
for your switch.)
Configuring the Switch To Access a RADIUS Server
This section describes the minimal commands for configuring a RADIUS
server to support Web-Auth and MAC Auth. For information on other RADIUS
command options, refer to chapter 6, “RADIUS Authentication, Authorization,
and Accounting” .
RADIUS Server Configuration Commands
radius-server
[host <
i
p-address
>]
below
[key <
global-key-string
>]
below
radius-server host <
i
p-address>
key <
server-specific key-string
>
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......