4-8
Configuring the RADIUS Server—Integrated with ProCurve Identity Driven Manager
Overview
Disadvantages of using the Windows domain include:
■
You must know an administrator username and password for the Win-
dows domain; otherwise, you cannot configure the NAC 800 to join the
domain.
■
If your NAC 800 loses connectivity to the domain controller (the server
running AD), it cannot authenticate users.
Having multiple domain controllers mitigates this disadvantage.
■
Your network must use one of these authentication methods:
•
MS-CHAPv1 or MS-CHAPv2
•
EAP-TTLS with MS-CHAPv2
•
PEAP with MS-CHAPv2
If you need to use a different method, use the NAC 800’s local database.
LDAP Server
Just as the NAC 800 can join a Windows domain and access AD, it can bind to
an LDAP server and search a directory. For example, your organization might
already have a directory that authenticates users and authorizes them for
various types of network access.
The NAC 800 can bind to these LDAP servers:
■
OpenLDAP
See “Configure Authentication to an OpenLDAP Server” on page 4-21.
■
Novell eDirectory
See “Configure Authentication to a Novell eDirectory Server” on page 4-26.
Advantages of using LDAP servers as the data store include:
■
IDM can import users from an LDAP server. When you also bind the NAC
800 to the LDAP server, you enable the NAC 800 to authenticate these
users without adding passwords to the user accounts in IDM.
■
Changes to a directory object are automatically available to all NAC 800s.
Disadvantages of using the LDAP servers include:
■
You must know the username and password for the root account of the
directory database in question; otherwise, you cannot configure the NAC
800 to bind to the directory.
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...