Configuring Triple Authentication; Overview; Triple Authentication Mechanism - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring triple authentication

Overview

Triple authentication enables an access port to perform Web, MAC, and 802.1X authentication. A
terminal can access the network if it passes one type of authentication.
Triple authentication is suitable for a LAN that comprises terminals that require different
authentication services, as shown in
perform MAC authentication for the printer, 802.1X authentication for the PC installed with the
802.1X client, and Web authentication for the Web user.
Figure 168 Triple authentication network diagram
802.1X authentication
802.1X client
In triple authentication, 802.1X authentication supports only the MAC-based access control method.
For more information about Web authentication, MAC authentication and 802.1X authentication, see
"Configuring Web

Triple authentication mechanism

The three types of authentication are triggered by different packets:
The access port performs MAC authentication for a terminal when it receives an ARP or DHCP
broadcast packet from the terminal for the first time. If the terminal passes MAC authentication,
the terminal can access the network. If the MAC authentication fails, the access port performs
802.1X or Web authentication.
The access port performs 802.1X authentication when it receives an EAP packet from an
802.1X client or a third-party client. If the unicast trigger feature of 802.1X is enabled on the
access port, any packet from the client can trigger an 802.1X authentication.
The access port performs Web authentication when it receives an HTTP packet from a terminal.
If a terminal triggers different types of authentication, the authentications are processed at the same
time. The failure of one type of authentication does not affect the others. When a terminal passes
one type of authentication, the other types of authentication are processed as follows:
If the terminal first passes MAC authentication, Web authentication is terminated immediately,
but 802.1X authentication will proceed. If the terminal also passes 802.1X authentication, the
802.1X authentication information will overwrite the MAC authentication information for the
Figure
IP network
Web authentication
MAC authentication
Printer
authentication,"
"Configuring MAC
168. The triple authentication-enabled access port can
AAA server
Web user
authentication," and
605
"Configuring
802.1X."

Advertisement

Table of Contents
loading

Table of Contents