91
Configuring EAD fast deployment
EAD is an HP integrated endpoint access control solution that enables the security client, security policy
server, access device, and third-party server to work together to improve the threat defensive capability
of a network. If a terminal device seeks to access an EAD network, it must have an EAD client, which
performs 802.1X authentication.
EAD fast deployment enables the access device to redirect a user seeking to access the network to
download and install EAD client. This function eliminates the tedious job of the administrator to deploy
EAD clients.
EAD fast deployment implementation
EAD fast deployment is implemented by the following functions:
•
•
Free IP
A free IP is a freely accessible network segment with a limited set of network resources, such as software
and DHCP servers. An unauthenticated user can access only this segment to download EAD client,
obtain a dynamic IP address from a DHCP server, or perform some other tasks to be compliant with the
network security strategy.
URL redirection
If an unauthenticated 802.1X user is using a web browser to access the network, the EAD fast
deployment function redirects the user to a specific URL. For example, the user might be redirected to the
EAD client software download page.
The server that provides the URL must be on the free IP accessible to unauthenticated users.
Configuration prerequisites
•
Enable 802.1X globally.
•
Enable 802.1X on the port, and set the port authorization mode to
auto
.
Configuration procedure
Configuring a free IP
When a free IP is configured, the EAD fast deployment is enabled. To allow a user to obtain a dynamic
IP address before passing 802.1X authentication, make sure that the DHCP server is on the free IP
segment.
To configure a free IP:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...