Nac 800 And 802.1X - HP ProCurve NAC 800 User Manual

Hide thumbs Also See for ProCurve NAC 800:
Table of Contents

Advertisement

802.1X Quarantine Method

NAC 800 and 802.1X

11-4

NAC 800 and 802.1X

When configured as 802.1X-enabled, NAC 800 can be installed with three
different configurations depending on your network environment:
Microsoft IAS and NAC 800 IAS Plug-in
With this method, the switch is configured with the IAS server IP
address as the RADIUS server host. When the switch performs the
RADIUS authentication, IAS authenticates the user. If successful, IAS
then calls the NAC 800 plug-in, which asks NAC 800 for the health
status of the endpoint. You can configure up to six NAC 800 server
URLs. The plug-in reads the list of servers over and over (iterates)
attempting to connect to one of them. Once a connection is made, the
NAC 800 plug-in uses that server URL until it is no longer available,
at which point it iterates over the list of servers again. If necessary,
the NAC 800 plug-in overwrites the RADIUS attributes to specify the
VLAN to place the endpoint into. IAS then returns the results to the
switch.
Proxying RADIUS requests to an existing RADIUS server
With this method, the switch is configured with the NAC 800 IP
address as the RADIUS server host. When the switch performs the
RADIUS authentication against the NAC 800 server, NAC 800 proxies
the request to another RADIUS server. As long as that server supports
the appropriate authentication methods used by the client it should
allow and authenticate the proxied requests. On successful authenti-
cation, when the end RADIUS server returns the proxied request NAC
800 overrides the RADIUS attributes which specify to the switch
which VLAN to place the endpoint in if necessary. NAC 800 then
returns the authentication results to the switch.
Using the built-in NAC 800 RADIUS server
With this method, all authentication takes place on the NAC 800
server. The switch is configured with the NAC 800 IP address as the
RADIUS server host. NAC 800 performs the authentication based on
the FreeRADIUS configuration, inserts RADIUS attributes specifying
into which VLAN to place the endpoint, and returns the result to the
switch.
When NAC 800 is used in an 802.1X network, the configuration is as shown in
figure 11-2, and the communication flow is shown in Figure 11-3 on page 11-6.

Advertisement

Table of Contents
loading

Table of Contents