5-15
Configuring the RADIUS Server—Without Identity Driven Manager
Configure the NAC 800 as a RADIUS Server
You must configure the NAC 800 to perform these functions:
■
Bind to the LDAP server
To complete the binding, the server submits a distinguished name (DN)
and password to the LDAP server. You must specify the DN and password
of an object with administrative rights. In addition, you must specify the
base DN. The base DN serves as the starting point for LDAP searches and
is typically the top level of the tree. The administrator object must be
under the specified base DN.
■
Search the LDAP server’s directory to check the user’s credentials and
group memberships.
•
With the user login filter, the NAC 800 looks up the account that
matches the name submitted by the end-user.
•
To check the end-user’s password, the NAC 800 requests the password
attribute for the account.
By default, the NAC 800 and the LDAP server communicate in plaintext
messages. You should configure the NAC 800 to complete TLS authentication
with the LDAP server, which increases security in several ways:
■
The NAC 800 and the LDAP server verify their identities to each other with
secure digital certificates—which ensures that they communicate user
account information to authorized devices only.
■
TLS creates an encrypted tunnel between the NAC 800 and the LDAP
server—which protects users’ information from eavesdroppers.
Configure Authentication to an OpenLDAP Server.
If your network
stores user accounts in OpenLDAP, follow these steps to configure the NAC
800’s authentication settings:
1.
Complete the steps listed in “Specify the Quarantine Method (802.1X)” on
page 5-8. You should see the window in Figure 5-4.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......