ProCurve 6200yl User's Guide Page 230

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 229
7-24
Configuring RADIUS Server Support for Switch Services
Configuring and Using RADIUS-Assigned Access Control Lists
Configuring the Switch To Support Dynamic Port
ACLs
An ACL configured in a RADIUS server is identified by the authentication
credentials of the client or group of clients the ACL is designed to support.
When a client authenticates with credentials associated with a particular ACL,
the switch applies that ACL to the switch port the client is using. To enable
the switch to forward a client’s credentials to the RADIUS server, you must
first configure RADIUS operation and an authentication method on the switch.
1. Configure RADIUS operation on the switch:
Syntax: radius-server host < ip-address > key < key-string >
This command configures the IP address and encryption key of a
RADIUS server. The server should be accessible to the switch and
configured to support authentication requests from clients using the
switch to access the network. For more on RADIUS configuration,
refer to chapter 6 ,“RADIUS Authentication and Accounting”.
2. Configure RADIUS network accounting on the switch (optional). RADIUS
network accounting is necessary to retrieve counter information if the cnt
(counter) option is included in any of the ACEs configured on the RADIUS
server.
Syntax: aaa accounting network < start-stop | stop-only > radius
Note Refer to the documentation provided with your RADIUS server for infor-
mation on how the server receives and manages network accounting
information, and how to perform any configuration steps necessary to
enable the server to support network accounting data from the switch.
3. Configure an authentication method. Options include 802.1X, Web authen-
tication, and MAC authentication. (You can configure 802.1X and either
Web or MAC authentication to operate simultaneously on the same ports.)
802.1X Option:
Syntax: aaa port-access authenticator < port-list >
aaa authentication port-access chap-radius
aaa port-access authenticator active
These commands configure 802.1X port-based access control on
the switch, and activates this feature on the specified ports. For
more on 802.1X configuration and operation, refer to chapter 13,
“Configuring Port-Based and User-Based Access Control
(802.1X)” in this guide.
Page view 229
1 2 ... 225 226 227 228 229 230 231 232 233 234 235 ... 595 596

Comments to this Manuals

No comments