7-3
Redundancy and Backup for RADIUS Services
Redundancy
If the NAC 800 contacts another device—such as an LDAP or proxy
RADIUS server—to check user credentials, two additional points of fail-
ure are possible—the data store and the link to the data store. If the server
goes down or the network connection fails, NAC 800 cannot reach its data
store to authenticate users.
Although storing credentials on individual NAC 800s’ local databases
eliminates the need to contact another device and eliminates this potential
failure point, it creates another issue: all NAC 800s and RADIUS servers
must have identical databases so that, if called upon, they can authenticate
any user. (ProCurve Identity Driven Manager, or IDM, simplifies this
process as explained below.)
Whichever data store you choose, consider the following issues:
•
Directory service
—If the data store is an LDAP-compliant directory
service, you must provide redundancy for the LDAP servers them-
selves. (This task is outside of the scope of this management and
configuration guide.) You must also plan for redundant pathways
between the RADIUS servers and the data store on the LDAP server.
N o t e
In the remainder of this chapter, the term
RADIUS server
will refer either
to a NAC 800 acting as a RADIUS server or a third-party RADIUS server.
•
NAC 800 local data store
—If you are storing credentials on the
NAC 800, IDM ensures that each NAC 800 includes the same user-
names and passwords. You enter the usernames and passwords once
on the IDM server, and it will configure them on each NAC 800 for you
when you deploy the policy.
■
Network paths
—You should build redundant links into your network
architecture. A single failed connection should never isolate one section
of the network from another.
Place the RADIUS Servers
Because you are trying to eliminate any single point of failure, you should not
connect your two redundant RADIUS servers to the same switch. Ideally, the
RADIUS servers should be connected to two different switches so that, if one
switch becomes unavailable, the other RADIUS server is not affected. (You
can also reduce the possibility of a switch failure by purchasing a switch that
is designed for high availability. For example, the ProCurve Switch 5400zl
Series has a dual-power supply, and the ProCurve Switch 8200zl Series has
dual management modules, dual fabric modules, and a dual-power supply. For
more information about these switches, visit
http://www.procurve.com
.)
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...