8-6
Configuring Port-Based and Client-Based Access Control (802.1X)
Overview
access from a master database in a single server (although you can use up to
three RADIUS servers to provide backups in case access to the primary server
fails). It also means a user can enter the same username and password pair
for authentication, regardless of which switch is the access point into the LAN.
Note that you can also configure 802.1X for authentication through the
switch’s local username and password instead of a RADIUS server, but doing
so increases the administrative burden, decentralizes username/password
administration, and reduces security by limiting authentication to one Oper-
ator/Manager password set for all users.
Providing a Path for Downloading 802.1X Supplicant Software.
For
clients that do not have the necessary 802.1X supplicant software, there is also
the option to configure the 802.1X Open VLAN mode. This mode allows you
to assign such clients to an isolated VLAN through which you can provide the
necessary supplicant software these clients need to begin the authentication
process. (Refer to “802.1X Open VLAN Mode” on page 8-26.)
Authenticating One Switch to Another.
802.1X authentication also
enables the switch to operate as a supplicant when connected to a port on
another switch running 802.1X authentication.
Figure 8-1. Example of an 802.1X Application
Accounting .
The switch also provides RADIUS Network accounting for
802.1X access. Refer to “RADIUS Authentication, Authorization and Account-
ing” on page 5-1.
RADIUS Server
LAN Core
802.1X-Aware
Client
(Supplicant)
Switch Running 802.1X and
Connected as a Supplicant
Switch Running 802.1X and
Operating as an Authenticator
Содержание ProCurve 2510-24
Страница 1: ...Access Security Guide 2510 www procurve com ProCurve Switches Q 11 XX 2510 24 U 11 XX 2510 48 ...
Страница 2: ......
Страница 3: ...ProCurve Series 2510 Switches Access Security Guide July 2008 ...
Страница 26: ...1 10 Getting Started Need Only a Quick Start ...
Страница 104: ...4 30 TACACS Authentication Configuring TACACS on the Switch ...
Страница 144: ...5 40 RADIUS Authentication Authorization and Accounting Messages Related to RADIUS Operation ...
Страница 174: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 196: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Страница 294: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Страница 308: ...10 14 Using Authorized IP Managers Operating Notes ...
Страница 316: ...8 Index ...
Страница 317: ......