
1-31
Overview of the ProCurve NAC 800
RADIUS Server
ProCurve NAC 800 RADIUS Capabilities
The ProCurve NAC 800 supports the following RADIUS capabilities:
■
Authenticating users against accounts stored in a variety of locations,
including:
•
Windows domain controllers (Active Directory [AD])
•
An OpenLDAP server
•
An eDirectory server
•
Another RADIUS server (proxying requests)
■
Authenticating users with a variety of protocols, including:
•
Extensible Authentication Protocol (EAP):
–
Protected EAP (PEAP) with Microsoft CHAP version 2
(MS-CHAPv2)
–
Transport Layer Security (TLS)
–
Tunneled TLS (TTLS) with Message Digest 5 (MD5)
–
Generic Token Card (GTC)
–
Lightweight EAP (LEAP)
■
Granting users rights, as follows:
•
Assigning users to a VLAN based on their endpoint integrity posture
■
Logging activity
The NAC 800 logs RADIUS events to this file:
/var/log/radius/radius.log
.
By default, the file stores a week’s worth of logs. Every month, the NAC
creates a new log file, and it saves up to four files.
RADIUS logs include:
•
Failed authentication attempts
•
Successful authentication attempts
•
Authentication requests from unknown NASs
■
Accounting
The NAC 800 can also act as a RADIUS accounting server. RADIUS
accounting reports are logged as files in this directory:
/var/log/radius/
radacct
.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......