HP 10500 Series Configuration Manual page 347

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

specifying 802.1X mandatory port authentication
domain, 92
specifying 802.1X supported domain name
delimiters, 97
specifying MAC authentication domain, 1 15
specifying portal authentication domain, 136
DoS attack (URPF), 268
DPD
IKE peer liveliness check, 322
dynamic binding entries
IPv4 source guard, 237
IPv6 source guard, 237
EAD
configuring free IP (EAD fast deployment), 106
configuring redirect URL (EAD fast deployment),
107
displaying fast deployment, 107
fast deployment configuration, 106, 108
free IP, 106
implementing fast deployment, 106
setting rule timer (EAD fast deployment), 107
troubleshooting fast deployment, 1 10
troubleshooting Web browser users not correctly
redirected, 1 10
URL redirection, 106
verifying fast deployment configuration, 109
EAP
802.1X packet format, 73
802.1X related protocols, 73
comparison of EAP relay and EAP termination
authentication modes (802.1X), 76
EAP-Message attribute (802.1X), 75
enabling 802.1X EAP relay, 86
enabling 802.1X EAP termination, 86
Message-Authentication attribute (802.1X), 75
over RADIUS (802.1X), 74
portal support, 127
portal support for authentication process, 130
relay authentication (802.1X), 77
termination authentication (802.1X), 78
EAPOL
802.1X packet format, 74
802.1X related protocols, 73
enabling
802.1X, 86
802.1X EAP relay, 86
802.1X EAP termination, 86
802.1X periodic online user re-authentication
function, 93
802.1X proxy detection function, 90
ACL checking for de-encapsulated IPsec packets,
310
ARP attack protection black hole routing, 252
FIPS mode, 296
first-time SSH authentication, 209, 210
invalid SPI recovery, 31 1
IPv4 source guard on port, 238
IPv6 ND attack defense source MAC packet
consistency check, 267
IPv6 source guard on port, 240
MFF, 275
MFF periodic gateway probe, 276
port security, 170
port security trap, 173
portal authentication, 133
RADIUS client service, 31
RADIUS trap function, 30
SSH server function, 203
SSH SFTP server function, 204
SYN cookie feature (TCP attack protection), 235
user profile, 189
enabling password control, 287
encapsulation
transport mode (IPsec), 300
tunnel mode (IPsec), 300
encryption
IPsec, 301
public key configuration, 195
public key management, 191
SSH configuration, 200
Endpoint Admission Defense. See EAD
establishing
SSH SFTP server connection, 212
SSH Stelnet server connection, 210
Ethernet (IPv6 ND attack defense), 266
exchange process (HWTACACS message), 7
exporting
host public key in specific format to a file, 193
local host public key, 192
feature
configuring port security features, 171
configuring port security intrusion protection, 172
configuring port security NTK, 172
MAC authentication ACL assignment, 1 12
MAC authentication guest VLAN, 1 12, 1 15
port security, 166
using 802.1X authentication with other features,
80
using MAC authentication with other features, 1 12
file (SFTP), 214
filtering
337

Advertisement

Table of Contents
loading

Table of Contents