6-80
RADIUS Authentication, Authorization, and Accounting
Dynamic Removal of Authentication Limits
Dynamic Removal of Authentication
Limits
Overview
In some situations, it is desirable to configure RADIUS attributes for down-
stream supplicant devices that allow dynamic removal of the 802.1X, MAC,
and Web authentication limits on the associated port of the authenticator
switch. This eliminates the need to manually reconfigure ports associated with
downstream 802.1X-capable devices, and MAC relay devices such as IP
phones, on the authenticator switches. When the RADIUS authentication ages
out, the authentication limits are dynamically restored. This enhancement
allows a common port policy to be configured on all access ports by creating
new RADIUS HP vendor-specific attributes (VSAs) that will dynamically
override the authentication limits. The changes are always applied to the port
on the authenticator switch associated with the supplicant being authenti-
cated.
N o t e
All the changes requested by the VSAs must be valid for the switch configura-
tion. For example, if either MAC-based or Web-based port access is configured
while 802.1X port access is in client mode, a RADIUS client with a VSA to
change the 802.1X port access to port-based mode is not allowed. 802.1X in
port-based mode is not allowed with MAC-based or web-based port access
types. However, if the authenticating client has VSAs to disable MAC-based
and Web-based authentication in conjunction with changing 802.1X to port-
based mode, then client authentication is allowed.
Configuring the RADIUS VSAs
Only RADIUS -authenticated port-access clients will be able to dynamically
change the port access settings using the new proprietary RADIUS VSAs. The
settings that can be overridden are:
•
Client limit (address limit with mac-based port access)
•
Disabling the port-access types
•
Setting the port mode in which 802.1X is operating
Содержание HP ProCurve Series 6600
Страница 2: ......
Страница 6: ...iv ...
Страница 26: ...xxiv ...
Страница 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Страница 204: ...4 72 Web and MAC Authentication Client Status ...
Страница 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Страница 756: ...16 8 Key Management System Configuring Key Chain Management ...
Страница 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Страница 777: ......