8-35
Configuring Port-Based and Client-Based Access Control (802.1X)
802.1X Open VLAN Mode
■
A client must either have a valid IP address configured before
connecting to the switch, or download one through the Unauthorized-
Client VLAN from a DHCP server. In the latter case, you will need to
provide DHCP services on the Unauthorized-Client VLAN.
■
Ensure that the switch is connected to a RADIUS server configured
to support authentication requests from clients using ports config-
ured as 802.1X authenticators. (The RADIUS server should not be on
the Unauthorized-Client VLAN.)
Note that as an alternative, you can configure the switch to use local
password authentication instead of RADIUS authentication. However,
this is less desirable because it means that all clients use the same
passwords and have the same access privileges. Also, you must use 802.1X
supplicant software that supports the use of local switch passwords.
C a u t i o n
Ensure that you do not introduce a security risk by allowing Unauthorized-
Client VLAN access to network services or resources that could be compro-
mised by an unauthorized client.
Configuring General 802.1X Operation:
These steps enable 802.1X
authentication, and must be done before configuring 802.1X VLAN operation.
1.
Enable 802.1X authentication on the individual ports you want to serve
as authenticators. (The switch automatically disables LACP on the ports
on which you enable 802.1X.) On the ports you will use as authenticators
with VLAN operation, ensure that the (default) port-control parameter is
set to
auto
. (Refer to “1. Enable 802.1X Authentication on Selected Ports”
on page 8-17.) This setting requires a client to support 802.1X authentica-
tion (with 802.1X supplicant operation) and to provide valid credentials
to get network access.
Syntax
:
aaa port-access authenticator e <
port-list
> control auto
Activates 802.1X port-access on ports you have configured as
authenticators.
Содержание ProCurve 2510-24
Страница 1: ...Access Security Guide 2510 www procurve com ProCurve Switches Q 11 XX 2510 24 U 11 XX 2510 48 ...
Страница 2: ......
Страница 3: ...ProCurve Series 2510 Switches Access Security Guide July 2008 ...
Страница 26: ...1 10 Getting Started Need Only a Quick Start ...
Страница 104: ...4 30 TACACS Authentication Configuring TACACS on the Switch ...
Страница 144: ...5 40 RADIUS Authentication Authorization and Accounting Messages Related to RADIUS Operation ...
Страница 174: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 196: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Страница 294: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Страница 308: ...10 14 Using Authorized IP Managers Operating Notes ...
Страница 316: ...8 Index ...
Страница 317: ......