HP FlexNetwork NJ5000 User Manual page 9

5g poe+ walljack
Table of Contents

Advertisement

802.1X configuration examples ······················································································································ 266
MAC-based 802.1X configuration example ···························································································· 266
802.X with ACL assignment configuration example ··············································································· 273
Configuring AAA ························································································· 282
Overview ························································································································································ 282
AAA application ······································································································································ 282
Domain-based user management ·········································································································· 283
Configuration prerequisites ···························································································································· 283
Recommended configuration procedure ································································································ 283
Configuring an ISP domain ···················································································································· 284
Configuring authentication methods for the ISP domain ········································································ 284
Configuring authorization methods for the ISP domain ·········································································· 286
Configuring accounting methods for the ISP domain ············································································· 287
AAA configuration example ···························································································································· 288
Configuring RADIUS ··················································································· 293
Overview ························································································································································ 293
Client/server model ································································································································ 293
Security and authentication mechanisms ······························································································· 293
Basic RADIUS message exchange process ·························································································· 294
RADIUS packet format ··························································································································· 294
Extended RADIUS attributes ·················································································································· 297
Protocols and standards ························································································································ 297
Configuring a RADIUS scheme ····················································································································· 298
Configuring common parameters ··········································································································· 299
Adding RADIUS servers ························································································································· 302
RADIUS configuration example ····················································································································· 303
Configuration guidelines ································································································································ 307
Configuring HWTACACS ············································································ 309
Recommended configuration procedure ········································································································ 309
Creating the HWTACACS scheme system ···································································································· 309
Configuring HWTACACS servers for the scheme ························································································· 310
Configuring HWTACACS communication parameters for the scheme ·························································· 311
HWTACACS configuration example ·············································································································· 314
Network requirements ···························································································································· 314
Configuring the HWTACACS server ······································································································ 314
Configuring the HPE NJ5000 5G PoE+ switch ······················································································ 314
Verifying the configuration ······················································································································ 319
Configuration guidelines ································································································································ 319
Configuring users ························································································ 321
Configuring a local user ································································································································· 321
Configuring a user group ······························································································································· 323
Managing certificates ·················································································· 325
Overview ························································································································································ 325
PKI terms ··············································································································································· 325
PKI architecture ······································································································································ 325
How PKI works ······································································································································· 326
PKI applications ····································································································································· 327
Recommended configuration procedures ······································································································ 327
Recommended configuration procedure for manual request ································································· 327
Recommended configuration procedure for automatic request ····························································· 329
Creating a PKI entity ······································································································································ 329
Creating a PKI domain ··································································································································· 330
Generating an RSA key pair ·························································································································· 333
Destroying the RSA key pair ·························································································································· 334
Retrieving and displaying a certificate ··········································································································· 334
Requesting a local certificate ························································································································· 336
Retrieving and displaying a CRL ···················································································································· 337
vii
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents