
4-16
Configuring the RADIUS Server—Integrated with ProCurve Identity Driven Manager
Configure the NAC 800 as a RADIUS Server
3.
Add user accounts to the local database through IDM.
You must complete two steps on the IDM server:
a.
Modify the NAC 800’s domain and select
Enable Local Authentica-
tion for ProCurve NAC devices
.
b.
Add users to the realm.
IDM automatically configures on the NAC 800 any user that you add
to the NAC 800’s realm. You must, however, configure passwords for
those users.
See the
ProCurve Identity Driven Management Users’ Guide
for more
detailed instructions in completing these steps.
4.
You are now ready to specify your network’s NASs. (See “Add NASs as
802.1X Devices” on page 4-40.)
Configure Authentication to a Windows Domain
The Windows Domain authentication method allows the NAC 800 to check
end-user credentials against credentials stored in AD.
The NAC 800 joins the domain. Then, when it receives an authentication
request from an end-user, the NAC 800 uses NT LAN Manager (NTLM) to query
a domain controller (a server that runs AD) and check the end-users’ creden-
tials.
To set up the Windows domain authentication method successfully, you must
ensure that:
■
Endpoints and NASs meet requirements for NTLM authentication:
•
End-users are members of the domain.
•
For 802.1X authentication, endpoints support PEAP or TTLS with MS-
CHAPv2 as the inner method.
N o t e
If your NASs or endpoints do not support the correct authentication
methods, the NAC 800 cannot authenticate end-users directly against AD.
You must either proxy authentication requests to another RADIUS server
or select local authentication in IDM to duplicate user accounts on the
NAC 800’s local directory.
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...