5-10
Configuring the RADIUS Server—Without Identity Driven Manager
Configure the NAC 800 as a RADIUS Server
4.
Select the
Access mode
.
If you are creating a cluster for RADIUS services only, the access mode
does not matter because the NAC 800 does not enforce quarantining.
However, you should disable testing as explained in Chapter 6: “Disabling
Endpoint Integrity Testing.”
5.
In the
Basic 802.1X settings
area, select
Local
for the
RADIUS server type
.
N o t e
The
Quarantine subnets
field only applies if the NAC 800 enforces endpoint
integrity. This setting allows the NAC 800 to respond to DNS requests from
endpoints in quarantine VLANs. You should have already set up the quarantine
VLANs in IDM.
You have now enabled the NAC 800 to make access-control decisions as a
RADIUS server. Next, you must configure the RADIUS server’s authentication
settings.
Configure Authentication Settings
To check 802.1X credentials, the NAC 800 draws on user accounts stored in
one of several locations:
■
A Windows domain (see “Configure Authentication to a Windows
Domain” on page 5-10)
■
An OpenLDAP server (see “Configure Authentication to an OpenLDAP
Server.” on page 5-15)
■
A Novell eDirectory server (see “Configure Authentication to a Novell
eDirectory Server” on page 5-19)
■
Another RADIUS server (see “Configure Authentication to a Proxy
RADIUS Server” on page 5-23)
N o t e
The
Manual
option for end-user authentication specifies the NAC 800’s local
database as the data store. However, IDM is required for this option.
Configure Authentication to a Windows Domain
The Windows domain authentication method allows the NAC 800 to check
end-user credentials against credentials stored in AD.
The NAC 800 joins the domain. Then, when it receives an authentication
request from an end-user, the NAC 800 uses NT LAN Manager (NTLM) to query
a domain controller (a server that runs AD) and check the end-user’s
credentials.
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...