General Setup Procedure For Web/Mac Authentication; Do These Steps Before You Configure Web/Mac Authentication - HP procurve 5300xl Series Access Security Manual

Hide thumbs Also See for procurve 5300xl Series:
Table of Contents

Advertisement

Web and MAC Authentication

General Setup Procedure for Web/MAC Authentication

3-12
General Setup Procedure for Web/MAC
Authentication
Do These Steps Before You Configure Web/MAC
Authentication
1. Configure a local username and password on the switch for both the
Operator (login) and Manager (enable) access levels. (While this is not
required for a Web- or MAC-based configuration, HP recommends that
you use a local user name and password pair, at least until your other
security measures are in place, to protect the switch configuration from
unauthorized access.)
2. Determine which ports on the switch you want to operate as authentica­
tors. Note that before you configure Web- or MAC-based authentication
on a port operating in an LACP trunk, you must remove the port from the
trunk. (refer to the "Note on Web/MAC Authentication and LACP" on
page 3-11.)
3. Determine whether any VLAN assignments are needed for authenticated
clients.
a. If you configure the RADIUS server to assign a VLAN for an authen­
ticated client, this assignment overrides any VLAN assignments con-
figured on the switch while the authenticated client session remains
active. Note that the VLAN must be statically configured on the
switch.
b. If there is no RADIUS-assigned VLAN, the port can join an "Authorized
VLAN" for the duration of the client session, if you choose to configure
one. This must be a port-based, statically configured VLAN on the
switch.
c. If there is neither a RADIUS-assigned VLAN or an "Authorized VLAN"
for an authenticated client session on a port, then the port's VLAN
membership remains unchanged during authenticated client ses­
sions. In this case, configure the port for the VLAN in which you want
it to operate during client sessions.
Note that when configuring a RADIUS server to assign a VLAN, you can
use either the VLAN's name or VID. For example, if a VLAN configured in
the switch has a VID of 100 and is named vlan100, you could configure the
RADIUS server to use either "100" or "vlan100" to specify the VLAN.

Advertisement

Table of Contents
loading

Table of Contents