4-30
Configuring the RADIUS Server—Integrated with ProCurve Identity Driven Manager
Configure the NAC 800 as a RADIUS Server
The password attribute (default “nspmPassword”) must match the attri-
bute used to store passwords in eDirectory accounts.
N o t e
Be careful when altering the default settings: if you cause searches to fail,
you effectively lock out all users.
9.
Check the
Use a secure connection (TLS)
box.
The NAC 800 and the eDirectory server perform a TLS handshake to
authenticate each other, as well as set up encryption keys to prevent
eavesdroppers from discovering credentials.
An eDirectory server, by default, requires secure connections.
10. If you checked the box in the previous step, verify that the NAC 800 has
the proper CA certificate.
The NAC 800 requires the CA certificate for the CA that signed the
eDirectory server’s certificate. Save this certificate on your management
station. Then click the
Browse
button next to
New certificate
to upload
it to the NAC 800.
11. To verify that the NAC 800 can successfully bind to the eDirectory server,
click the
test settings
button.
See “Test Authentication Settings” on page 4-35 for more information on
setting up the test.
12. You are now ready to specify your network’s NASs. (See “Add NASs as
802.1X Devices” on page 4-40.)
Configure Authentication to a Proxy RADIUS Server
If your network has an existing RADIUS server, you can configure the NAC 800
to proxy end-user authentication requests to that server.
N o t e
Check the EAP methods supported by the proxy RADIUS server. The server
must
use only those methods, such as PEAP, that include the username in
plaintext.
Follow these steps:
1.
Complete the steps listed in “Specify the Quarantine Method (802.1X)” on
page 4-12. You should see the window illustrated in Figure 4-9.
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...