![HP HP ProCurve Series 6600 Access Security Manual Download Page 262](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101262.webp)
6-28
RADIUS Authentication, Authorization, and Accounting
Cached Reauthentication
Cached Reauthentication
Cached reauthentication allows 802.1X, web, or MAC reauthentications to
succeed when the RADIUS server is unavailable. Users already authenticated
retain their currently-assigned RADIUS attributes. Uninterrupted service is
provided for authenticated users with RADIUS-assigned VLANS if the RADIUS
server becomes temporarily unavailable during periodic reauthentications.
Cached reauthentication is similar to the authorized authentication method
in that user credentials are not checked. Any user credentials are valid even
if they are different from those used during the last successful authentication
of the same session. However, cached reauthentication maintains the current
session attributes, unlike the authorized authentication method. New authen-
tications are not allowed. The RADIUS server can be the only allowed source
of session attributes for authenticated users.
Reauthentications are not disabled when the RADIUS server is unavailable.
The switch initiates reauthentications of clients at the specified period and
the clients must comply with the requirements for the reauthentication pro-
cedure exactly as is done for the authorized authentication method.
The table below summarizes the differences between the authorized method
and the cached reauthentication method.
Cached reauthentication is supported for 802.1X, Web authentication, and
MAC authentication. For more information about Web/MAC authentication,
see “Web and MAC Authentication” in the
Access Security Guide
for your
switch. For more information on 802.1X, see “Configuring Port-Based and
User-Based Access Control (802.1X) in the
Access Security Guide
for your
switch.
Authorized
Cached Reauthentication
New authentications are allowed when RADIUS server is
unreachable.
New authentications are not allowed when RADIUS server
is unreachable.
All previously RADIUS-assigned attributes are voided
and replaced by switch-configured values on reauthen-
tication when RADIUS server is unreachable.
All previously assigned attributes remain in effect on reau-
thentication when RADIUS server is unreachable.
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......