Aaa Implementation On The Device - HP MSR Series Configuration Manual

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

6.
The LDAP client sends an authorization search request with the username of the Telnet user to
the LDAP server. If the user uses the same LDAP server for authentication and authorization,
the client sends the request with the saved user DN of the Telnet user to the LDAP server.
7.
After receiving the request, the LDAP server searches for the user information by the base DN,
search scope, filtering conditions, and LDAP attributes. If a match is found, the LDAP server
sends a response to notify the LDAP client of the successful search.
8.
After successful authorization, the LDAP client notifies the user of the successful login.

AAA implementation on the device

This section describes AAA user management and methods.
User management based on ISP domains and user access types
AAA manages users based on the users' ISP domains and access types.
On a NAS, each user belongs to one ISP domain. The NAS determines the ISP domain to which a
user belongs based on the username entered by the user at login.
Figure 9 Determining the ISP domain for a user by username
 
AAA manages users in the same ISP domain based on the users' access types. The device supports
the following user access types:
LAN—LAN users must pass 802.1X or MAC authentication to come online.
Login—Login users include SSH, Telnet, FTP, and terminal users who log in to the device.
Terminal users can access through a console, AUX, or Async port.
ADVPN.
X.25 PAD.
Portal—Portal users must pass portal authentication to access the network.
PPP.
IPoE—IPoE users include Layer 2 and Layer 3 leased line users and Set Top Box (STB) users.
Web—Web users log in to the Web interface of the device through HTTP or HTTPS.
SSL VPN.
NOTE:
The device also provides authentication modules (such as 802.1X) for implementation of user
authentication management policies. If you configure these authentication modules, the ISP
domains for users of the access types depend on the configuration of the authentication modules.
12

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents