System Configuration
Remote—In more complex deployments, it is often impossible (in the case of multiple
■
Enforcement servers or multiple DHCP servers) or undesirable to span switch ports. In this case
the DHCP traffic monitoring and endpoint detection can be run remotely by installing and
configuring the endpoint activity capture software on each DHCP server involved in the 802.1X
deployment. In this case, choose the remote option.
Local—In simple configurations, it is possible to span, or mirror, the switch port into which the
■
DHCP server is connected. The eth1 interface of the Enforcement server is then plugged into the
spanned port and endpoint traffic is monitored on the eth1 interface. In this case, choose the local
option.
2 Enter one or more quarantined subnets, separated by commas in the Quarantine subnets text field.
All subnets should be entered using CIDR addresses.
3 Click ok.
Authentication Settings
Selecting the RADIUS Authentication method
To select the RADIUS authentication method:
Home window>>System configuration>>Quarantining>>802.1X quarantine method radio button
1 Select the Local radio button in the Basic 802.1X settings area.
2 Select an End-user authentication method:
Manual—RADIUS server authentication settings are configured manually from the command
■
line. See
Windows domain—Authentication requests are handled by a Windows domain through NTLM
■
protocol. The ES must be able to join to the domain for this to work. See
Domain Settings" on page 80
OpenLDAP—User credentials are queried from an OpenLDAP directory service. See
■
"Configuring OpenLDAP Settings" on page 82
Proxy—Authentication requests are proxied to a remote RADIUS server configured to allow the
■
ES as a client NAS.
3 Click ok.
Configuring Windows Domain Settings
To configure Windows domain settings:
Home window>>System configuration>>Quarantining>>802.1X Quarantine method radio
button>>Local radio button
80
"Enabling Sentriant AG for 802.1X" on page 240
for more information.
for configuration information.
for more information.
Sentriant AG Software Users Guide, Version 5.3
"Configuring Windows