Web and MAC Authentication
Overview
N o t e
A proxy server is not supported for use by a browser on a client device that
accesses the network through a port configured for web authentication.
■
In the login page, a client enters a username and password, which the
switch forwards to a RADIUS server for authentication. After authenticat
ing a client, the switch grants access to the secured network. Besides a
web browser, the client needs no special supplicant software.
MAC Authentication
The MAC Authentication (MAC-Auth) method grants access to a secure
network by authenticating devices for access to the network. When a device
connects to the switch, either by direct link or through the network, the switch
forwards the device’s MAC address to the RADIUS server for authentication.
The RADIUS server uses the device MAC address as the username and
password, and grants or denies network access in the same way that it does
for clients capable of interactive logons. (The process does not use either a
client device configuration or a logon session.) MAC authentication is well-
suited for clients that are not capable of providing interactive logons, such as
telephones, printers, and wireless access points. Also, because most RADIUS
servers allow for authentication to depend on the source switch and port
through which the client connects to the network, you can use MAC-Auth to
“lock” a particular device to a specific switch and port.
N o t e
802.1X port-access, Web authentication, and MAC authentication can be
configured at the same time on the same port. A maximum of eight clients is
supported on the port. (The default is one client.)
Web and/or MAC authentication and MAC lockdown, MAC lockout, and port-
security are mutually exclusive on a given port. If you configure any of these
authentication methods on a port, you must disable LACP on the port.
Concurrent Web and MAC Authentication
Web authentication and MAC authentication can be configured at the same
time on a port. It is assumed that MAC authentication will use an existing MAC
address. The following conditions apply for concurrent Web and MAC authen
tication:
■
A specific MAC address cannot be authenticated by both Web and MAC
authentication at the same time.
3-3
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...