
5-11
Configuring the RADIUS Server—Without Identity Driven Manager
Configure the NAC 800 as a RADIUS Server
To set up the Windows domain authentication method successfully, you must
ensure that:
■
Endpoints and NASs meet requirements for NTLM authentication:
•
End-users are members of the domain.
•
For 802.1X authentication, endpoints support PEAP or TTLS with MS-
CHAPv2 as the inner method.
N o t e
If your NASs or endpoints do not support the correct authentication
methods, the NAC 800 cannot authenticate end-users directly against AD.
■
The NAC 800 (the CS or ESs) can join the domain:
•
You need the username and password of an account with the right to
add devices to the domain (an administrator account).
•
The NAC 800’s hostname must be fully qualified with your domain’s
name—for example,
nac.mydomain.com
, not
nac
.
See “Edit MS or CS Network Settings” on page 3-18 of Chapter 3:
“Initial Setup of the ProCurve NAC 800” for instructions on changing
the hostname.
•
The NAC 800 requires a valid DNS server address (which allows it to
resolve the domain controller’s FQDN).
To specify the DNS server, see “Edit MS or CS Network Settings” on
page 3-18 of Chapter 3: “Initial Setup of the ProCurve NAC 800.”
•
Your network’s DNS servers must have forward lookup entries for the
NAC 800 and for the domain controller. It must also have the correct
reverse lookup zones.
•
The NAC 800’s clock is synced with the domain controller’s clock.
Default Windows server settings require the NAC 800’s time to be
within five minutes of the domain controller’s time to prevent replay
attacks. Either verify that both devices receive their clock from an
NTP server or change the setting on the domain controller.
Follow these steps to configure end-user authentication against a Windows
domain:
1.
Complete the steps listed in “Specify the Quarantine Method (802.1X)” on
page 5-8. You should see the window in Figure 5-2.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......