8-1
8
Configuring Port-Based and Client-Based
Access Control (802.1X)
Contents
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-3
Why Use Port-Based or Client-Based Access Control? . . . . . . . . . . . . 8-3
General Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-3
User Authentication Methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-4
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-7
General 802.1X Authenticator Operation . . . . . . . . . . . . . . . . . . . . . . . . . . 8-10
Example of the Authentication Process . . . . . . . . . . . . . . . . . . . . . . . . 8-10
Switch-Port Supplicant Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-11
General Operating Rules and Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-12
General Setup Procedure for 802.1X Access Control . . . . . . . . . . . . . . . . 8-14
Do These Steps Before You Configure 802.1X Operation . . . . . . . . . 8-14
Overview: Configuring 802.1X Authentication on the Switch . . . . . . 8-15
Configuring Switch Ports as 802.1X Authenticators . . . . . . . . . . . . . . . . . 8-17
1. Enable 802.1X Authentication on Selected Ports . . . . . . . . . . . . . . 8-17
2. Reconfigure Settings for Port-Access . . . . . . . . . . . . . . . . . . . . . . . . 8-20
3. Configure the 802.1X Authentication Method . . . . . . . . . . . . . . . . . 8-23
4. Enter the RADIUS Host IP Address(es) . . . . . . . . . . . . . . . . . . . . . . 8-24
5. Enable 802.1X Authentication on the Switch . . . . . . . . . . . . . . . . . 8-24
6. Optionally Resetting Authenticator Operation . . . . . . . . . . . . . . . . 8-25
802.1X Open VLAN Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-26
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-26
VLAN Membership Priorities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-27
Use Models for 802.1X Open VLAN Modes . . . . . . . . . . . . . . . . . . . . . 8-28
Operating Rules for Authorized-Client and
Unauthorized-Client VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-31
Содержание ProCurve 2510-24
Страница 1: ...Access Security Guide 2510 www procurve com ProCurve Switches Q 11 XX 2510 24 U 11 XX 2510 48 ...
Страница 2: ......
Страница 3: ...ProCurve Series 2510 Switches Access Security Guide July 2008 ...
Страница 26: ...1 10 Getting Started Need Only a Quick Start ...
Страница 104: ...4 30 TACACS Authentication Configuring TACACS on the Switch ...
Страница 144: ...5 40 RADIUS Authentication Authorization and Accounting Messages Related to RADIUS Operation ...
Страница 174: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 196: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Страница 294: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Страница 308: ...10 14 Using Authorized IP Managers Operating Notes ...
Страница 316: ...8 Index ...
Страница 317: ......