8-3
Configuring Port-Based and Client-Based Access Control (802.1X)
Overview
Overview
Why Use Port-Based or Client-Based Access Control?
Local Area Networks are often deployed in a way that allows unauthorized
clients to attach to network devices, or allows unauthorized users to get
access to unattended clients on a network. Also, the use of DHCP services and
zero configuration make access to networking services easily available. This
exposes the network to unauthorized use and malicious attacks. While access
to the network should be made easy, uncontrolled and unauthorized access
is usually not desirable. 802.1X simplifies security management by providing
access control along with the ability to control user profiles from up to three
RADIUS servers while allowing a given user to use the same entering valid
user credentials for access from multiple points within the network.
General Features
802.1X on the ProCurve switches covered in this manual includes the follow-
ing:
■
Switch operation as both an authenticator (for supplicants having a
point-to-point connection to the switch) and as a supplicant for point-
to-point connections to other 802.1X-aware switches.
•
Authentication of 802.1X clients using a RADIUS server and either
EAP (Extensible Authentication Protocol) or CHAP (Challenge Hand-
shake Authentication Protocol).
•
Provision for enabling clients that do not have 802.1 supplicant soft-
ware to use the switch as a path for downloading the software and
initiating the authentication process (802.1X Open VLAN mode).
•
Client-Based access control option with support for up to 2 authenti-
Feature
Default
Menu
CLI
Web
Configuring Switch Ports as 802.1X Authenticators
Disabled
n/a
page 8-17
n/a
Configuring 802.1X Open VLAN Mode
Disabled
n/a
page 8-26
n/a
Configuring Switch Ports to Operate as 802.1X Supplicants
Disabled
n/a
page 8-42
n/a
Displaying 802.1X Configuration, Statistics, and Counters
n/a
n/a
page 8-47
n/a
How 802.1X Affects VLAN Operation
n/a
n/a
page 8-54
n/a
RADIUS Authentication and Accounting
Refer to “RADIUS Authentication, Authorization
and Accounting” on page 5-1
Summary of Contents for ProCurve 2510G Series
Page 1: ...Access Security Guide www procurve com ProCurve Series 2510G Switches Y 11 XX ...
Page 2: ......
Page 3: ...ProCurve Series 2510G Switches Access Security Guide June 2008 ...
Page 12: ...x ...
Page 26: ...1 10 Getting Started Need Only a Quick Start ...
Page 105: ...4 31 TACACS Authentication Configuring TACACS on the Switch ...
Page 106: ...4 32 TACACS Authentication Configuring TACACS on the Switch ...
Page 176: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 198: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Page 296: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Page 310: ...10 14 Using Authorized IP Managers Operating Notes ...
Page 318: ...8 Index ...
Page 319: ......