Ead Configuration; Configuration Prerequisites; Configuring Ead - H3C S7500 Series Operation Manual

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – AAA & RADIUS & HWTACACS & EAD
H3C S7500 Series Ethernet Switches
The security client (software installed on PC) checks the security status of a client that
just passes the authentication, and interacts with the security policy server. If the client
is not compliant with the security standard, the security policy server issues ACL control
packets to the switch to control which resources the client can access.
After the client's vulnerability is fixed and it is compliant with the required security
standard, the security client passes the security state of the client to the security policy
server, which then reissues an ACL to the switch to assign the access right to the client
so that it can access more network resources.

2.3 EAD Configuration

2.3.1 Configuration prerequisites

EAD is implemented typically in RADIUS scheme. Before configuring EAD, perform the
following configuration:
Configuring the attributes, such as the user name, user type, and password for
access users. If local authentication is to be performed, you need to configure
these attributes on the switch; if remote authentication is to be performed, you
need to configure these attributes on the AAA sever.
Configuring a RADIUS scheme.
Associating domain with RADIUS scheme.
For the detailed configuration procedure, refer to
Configuration.

2.3.2 Configuring EAD

Table 2-1 EAD configuration
To do...
Enter system view
Enter RADIUS
scheme view
Configure the
RADIUS server type
to extended
Configure the IP
address for the
security policy server
Use the command...
system-view
radius scheme
radius-scheme-name
server-type extended
security-policy-server
ip-address
2-3
Chapter 2 EAD Configuration
AAA & RADIUS & HWTACACS
Remarks
Optional
By default, for a new RADIUS
scheme, the server type is
standard; The type of RADIUS
server in the default RADIUS
scheme system is extended.
Optional
This configuration is optional if
the security policy server and
RADIUS server run on the same
machine; otherwise, it is required.

Advertisement

Table of Contents
loading

Table of Contents