HPE Moonshot 45Gc Security Configuration Manual page 4

Switch module
Table of Contents

Advertisement

Authorization VLAN ·································································································································· 72
Guest VLAN ············································································································································· 74
Auth-Fail VLAN ········································································································································ 75
Critical VLAN ············································································································································ 76
Using 802.1X authentication with other features ····························································································· 78
ACL assignment ······································································································································· 78
User profile assignment ··························································································································· 79
EAD assistant ··········································································································································· 79
Configuration prerequisites ······························································································································ 79
802.1X configuration task list ··························································································································· 80
Enabling 802.1X ··············································································································································· 80
Enabling EAP relay or EAP termination ··········································································································· 81
Setting the port authorization state ·················································································································· 81
Specifying an access control method ·············································································································· 82
Setting the maximum number of concurrent 802.1X users on a port ······························································· 82
Setting the maximum number of authentication request attempts ··································································· 82
Setting the 802.1X authentication timeout timers ···························································································· 83
Configuring the online user handshake feature ······························································································· 83
Configuration guidelines ··························································································································· 83
Configuration procedure ··························································································································· 84
Configuring the authentication trigger feature ·································································································· 84
Configuration guidelines ··························································································································· 84
Configuration procedure ··························································································································· 84
Specifying a mandatory authentication domain on a port ················································································ 85
Setting the quiet timer ······································································································································ 85
Enabling the periodic online user reauthentication feature ·············································································· 86
Configuring an 802.1X guest VLAN ················································································································· 86
Configuration guidelines ··························································································································· 86
Configuration prerequisites ······················································································································ 87
Configuration procedure ··························································································································· 87
Enabling 802.1X guest VLAN assignment delay ····························································································· 87
Configuring an 802.1X Auth-Fail VLAN ··········································································································· 88
Configuration guidelines ··························································································································· 88
Configuration prerequisites ······················································································································ 89
Configuration procedure ··························································································································· 89
Configuring an 802.1X critical VLAN ················································································································ 89
Configuration guidelines ··························································································································· 89
Configuration prerequisites ······················································································································ 89
Configuration procedure ··························································································································· 90
Enabling 802.1X critical voice VLAN ················································································································ 90
Configuration prerequisites ······················································································································ 90
Configuration procedure ··························································································································· 91
Sending 802.1X protocol packets out of a port without VLAN tags ································································· 91
Specifying supported domain name delimiters ································································································ 91
Configuring the EAD assistant feature ············································································································· 92
Displaying and maintaining 802.1X ·················································································································· 93
802.1X authentication configuration examples ································································································ 93
Basic 802.1X authentication configuration example ················································································ 93
802.1X guest VLAN and authorization VLAN configuration example ······················································ 95
802.1X with ACL assignment configuration example ··············································································· 98
802.1X with EAD assistant configuration example ··················································································· 99
Troubleshooting 802.1X ································································································································· 102
EAD assistant for Web browser users ··································································································· 102
Configuring MAC authentication ································································· 103
Overview ························································································································································ 103
User account policies ····························································································································· 103
Authentication methods ·························································································································· 103
VLAN assignment ·································································································································· 103
ACL assignment ····································································································································· 105
User profile assignment ························································································································· 106
Periodic MAC reauthentication ··············································································································· 106
ii
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Advertisement

Table of Contents
loading

Table of Contents