4-8
Configuring the RADIUS Server—Integrated with ProCurve Identity Driven Manager
Overview
Disadvantages of using the Windows domain include:
■
You must know an administrator username and password for the Win-
dows domain; otherwise, you cannot configure the NAC 800 to join the
domain.
■
If your NAC 800 loses connectivity to the domain controller (the server
running AD), it cannot authenticate users.
Having multiple domain controllers mitigates this disadvantage.
■
Your network must use one of these authentication methods:
•
MS-CHAPv1 or MS-CHAPv2
•
EAP-TTLS with MS-CHAPv2
•
PEAP with MS-CHAPv2
If you need to use a different method, use the NAC 800’s local database.
LDAP Server
Just as the NAC 800 can join a Windows domain and access AD, it can bind to
an LDAP server and search a directory. For example, your organization might
already have a directory that authenticates users and authorizes them for
various types of network access.
The NAC 800 can bind to these LDAP servers:
■
OpenLDAP
See “Configure Authentication to an OpenLDAP Server” on page 4-21.
■
Novell eDirectory
See “Configure Authentication to a Novell eDirectory Server” on page 4-26.
Advantages of using LDAP servers as the data store include:
■
IDM can import users from an LDAP server. When you also bind the NAC
800 to the LDAP server, you enable the NAC 800 to authenticate these
users without adding passwords to the user accounts in IDM.
■
Changes to a directory object are automatically available to all NAC 800s.
Disadvantages of using the LDAP servers include:
■
You must know the username and password for the root account of the
directory database in question; otherwise, you cannot configure the NAC
800 to bind to the directory.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......