4-4
Configuring the RADIUS Server—Integrated with ProCurve Identity Driven Manager
Overview
Authentication Protocols
An authentication server receives an endpoints’ credentials via an authentica-
tion protocol. With 802.1X, the authentication protocol is always EAP, and the
NAC 800 and the endpoint negotiate the method. The NAC 800 supports these
EAP methods:
■
Protected EAP (PEAP) with:
•
MS-CHAPv2
•
Generic Token Card (GTC)
■
Transport Layer Security (TLS)
■
Tunneled TLS (TTLS) with:
•
MS-CHAPv2
•
Generic Token Card (GTC)
■
Lightweight EAP (LEAP)—not recommended
The NAC 800 first suggests PEAP with MS-CHAPv2.
An endpoint requires a client that supports at least one of the listed EAP
methods. For example, a Windows XP workstation has an 802.1X client
available to all network connections, and this client supports EAP-TLS and
PEAP with MS-CHAPv2. Older workstations might require the installation of
a vendor client for 802.1X authentication.
Table 4-1. Port Authentication Methods and Authentication
Protocols
Dynamic or User-Based Settings
Dynamic or user-based settings allow you to customize users’ network access
according to identity and are an important component of the ProCurve Adap-
tive Edge Architecture (AEA). The RADIUS server is responsible for matching
an authenticated user to the correct settings for that user.
Dynamic settings supported on the NAC 800 include:
■
Virtual local area network (VLAN) assignments
■
Access control lists (ACLs)
■
Rate limits
Port/Wireless
Authentication Method
Selection Method for Authentication
Protocol
802.1X
NAC 800 and endpoint negotiation—NAC
suggests PEAP with MS-CHAPv2 first.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......