HPE FlexNetwork 10500 Series Security Configuration Manual page 629

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Figure 170 Network diagram
802.1X client
Printer
Web user
Configuration prerequisites and guidelines
Make sure the terminals, the servers, and the device can reach each other.
Configure the RADIUS server to provide normal authentication, authorization, and accounting
for users. In this example, configure the following on the RADIUS server:
An 802.1X user with username userdot.
A Web authentication user with username userpt.
A MAC authentication user with a username and password both being the MAC address of
the printer f07d6870725f.
An authorization VLAN (VLAN 3).
Configure the IP address of server update as the authentication-free IP address.
Edit authentication pages, compress the pages to a .zip file named defaultfile and upload
the .zip file to the device by FTP.
Set the DHCP lease according to the network condition and how the terminals update their IP
addresses.
A short lease is recommended to shorten the time that terminals use to re-acquire IP addresses
after passing or failing authentication. This example uses the lease of 1 minute.
Some terminals do not need to wait for the lease to update their IP addresses. For example, the
iNode 802.1X client can automatically renew its IP address after disconnecting from the server.
Configuration procedure
1.
Configure DHCP:
# Configure VLANs and IP addresses for the VLAN interfaces, and add ports to specific VLANs.
(Details not shown.)
# Enable DHCP.
<Device> system-view
[Device] dhcp enable
# Exclude the IP address of the update server from dynamic address assignment.
[Device] dhcp server forbidden-ip 2.2.2.2
# Configure DHCP address pool 1 to assign IP addresses and other configuration parameters
to clients on subnet 192.168.1.0.
[Device] dhcp server ip-pool 1
[Device-dhcp-pool-1] network 192.168.1.0 mask 255.255.255.0
[Device-dhcp-pool-1] expired day 0 hour 0 minute 1
[Device-dhcp-pool-1] gateway-list 192.168.1.1
Loop0
4.4.4.4/32
GE1/0/1
Vlan-int8
192.168.1.1/24
Vlan-int2
Vlan-int1
2.2.2.1/24
1.1.1.1/24
Update server
2.2.2.2/24
612
Vlan-int3
3.3.3.1/24
IP network
Device
RADIUS server
1.1.1.2/24

Advertisement

Table of Contents
loading

Table of Contents