4-62
Web and MAC Authentication
Configuring MAC Authentication on the Switch
Diagram of the Registration Process
Figure 4-38. Example of Registration Process Using Redirection
Client
Switch
RADIUS
Web Server
Packet is sent
RADIUS request is made
Client fails authentication
Client is put
in unauth
MAC-auth
redirect
state.
Client sends DHCP request
Switch sends its IP address
ARP/DNS requests handled
Client requests Web page
Switch takes request and
redirects to web server.
HTTP request for initial registration page includes
client MAC, client port, switch IP or MAC
Initial registration page returned. Switch enables NAT
so all subsequent requests go directly to web server
Initial registration page
Switch filters all traffic; only
forwards HTTP traffic destined
to configured web server.
RADIUS is updated with client’s
username, password, profile
HTTP request/response
HTTP request/response
Client in redirect state until time exceeds
configured timeout or switch receives an
SNMP deauthentication request from the
Web server
1
4
5
2
3
6
7
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......