
System Configuration
73
no
vd
ocx
(e
n)
24
Ma
rch 20
09
Section 3.11.2, “Authentication Settings,” on page 74
Section 3.11.3, “Adding 802.1X Devices,” on page 79
Section 3.11.4, “Testing the Connection to a Device,” on page 80
Section 3.11.5, “Cisco IOS,” on page 82
Section 3.11.6, “Cisco CatOS,” on page 84
Section 3.11.7, “Enterasys,” on page 86
Section 3.11.8, “Extreme ExtremeWare,” on page 88
Section 3.11.9, “Extreme XOS,” on page 90
Section 3.11.10, “Foundry,” on page 92
Section 3.11.11, “HP ProCurve Switch,” on page 94
Section 3.11.12, “HP ProCurve WESM xl or HP ProCurve WESM zl,” on page 97
Section 3.11.13, “HP ProCurve 420 AP or HP ProCurve 530 AP,” on page 99
Section 3.11.14, “Nortel,” on page 101
Section 3.11.15, “Other,” on page 103
3.11.1 Entering Basic 802.1X Settings
To enter basic 802.1X settings:
Home window>>System configuration>>Quarantining>>802.1X quarantine method radio button
1
In 802.1X enforcement mode, the Enforcement servers must be able monitor DHCP
conversations and detect endpoints by sniffing network traffic as it flows between the DHCP
server and the endpoints. Select an
Endpoint detection location
radio button as
follows:
Remote
— In more complex deployments, it is often impossible (in the case of multiple
Enforcement servers or multiple DHCP servers) or undesirable to span switch ports. In
this case the DHCP traffic monitoring and endpoint detection can be run remotely by
installing and configuring the endpoint activity capture software on each DHCP server
involved in the 802.1X deployment. In this case, choose the remote option.
Local
— In simple configurations, it is possible to span, or mirror, the switch port into
which the DHCP server is connected. The eth1 interface of the Enforcement server is then
plugged into the spanned port and endpoint traffic is monitored on the eth1 interface. In
this case, choose the local option.
2
Enter one or more non-quarantined subnets, separated by commas in the
Quarantine
subnets
text field. All subnets should be entered using CIDR addresses.
3
Select a
RADIUS server type
by selecting one of the following radio buttons:
Local
— Enables a local RADIUS server on the ES which can be configured to perform
authentication itself or proxy to another server.
Remote IAS
— Disables the local RADIUS server so that an IAS server configured with
the NAC IAS plug-in to point to an ES can be used instead. When possible, a local
RADIUS server that proxies to the IAS server should be the preferred configuration.
4
Click
ok
.
Summary of Contents for ZENworks Network Access Control 5.0
Page 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Page 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...