Configuring Port-Based and Client-Based Access Control (802.1X)
Terminology
local authentication is used, in which case the switch performs this
function using its own username and password for authenticating a
supplicant).
Authenticator:
In ProCurve applications, a switch that requires a supplicant
to provide the proper credentials before being allowed access to the
network.
CHAP (MD5):
Challenge Handshake Authentication Protocol.
Client:
In this application, an end-node device such as a management station,
workstation, or mobile PC linked to the switch through a point-to-point
LAN link.
Client-Based Authentication:
The 802.1X extension in the switches cov
ered in this guide. In this operation, multiple clients on the same port must
individually authenticate themselves.
Guest VLAN:
See “Unauthorized-Client VLAN”.
EAP
(Extensible Authentication Protocol)
:
EAP enables network access that
supports multiple authentication methods.
EAPOL:
Extensible Authentication Protocol Over LAN,
as defined in the
802.1X standard
.
Friendly Client:
A client that does not pose a security risk if given access to
the switch and your network.
MD5:
An algorithm for calculating a unique digital signature over a stream of
bytes. It is used by CHAP to perform authentication without revealing the
shared secret (password).
PVID (Port VID):
This is the VLAN ID for the untagged VLAN to which an
802.1X port belongs.
Port-Based Authentication:
In this operation, the first client on a port to
authenticate itself unblocks the port for the duration of the client’s 802.1X-
authenticated session. The switches covered in this guide use port-based
authentication.
Static VLAN:
A VLAN that has been configured as “permanent” on the switch
by using the CLI
vlan <
vid
>
command or the Menu interface.
10-7
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......