Table Of Contents - HP 3600 v2 Series Security Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Contents
AAA configuration ······················································································································································· 1
AAA overview ··································································································································································· 1
RADIUS ······································································································································································ 2
HWTACACS ····························································································································································· 7
Domain-based user management ··························································································································· 9
RADIUS server feature of the switch ···················································································································· 10
AAA across MPLS L3VPNs ··································································································································· 11
Protocols and standards ······································································································································· 11
RADIUS attributes ·················································································································································· 12
AAA configuration considerations and task list ·········································································································· 15
Configuring AAA schemes ············································································································································ 16
Configuring local users ········································································································································· 16
Configuring RADIUS schemes ······························································································································ 20
Configuring HWTACACS schemes ····················································································································· 33
Configuring AAA methods for ISP domains ················································································································ 39
Configuration prerequisites ·································································································································· 39
Creating an ISP domain ······································································································································· 39
Configuring ISP domain attributes ······················································································································· 40
Configuring AAA authentication methods for an ISP domain ·········································································· 41
Configuring AAA authorization methods for an ISP domain ··········································································· 42
Configuring AAA accounting methods for an ISP domain ··············································································· 44
Tearing down user connections ···································································································································· 45
Configuring a NAS ID-VLAN binding ·························································································································· 46
Specifying the device ID used in stateful failover mode ···························································································· 46
Configuring a switch as a RADIUS server ··················································································································· 47
RADIUS server functions configuration task list ·································································································· 47
Configuring a RADIUS user ·································································································································· 47
Specifying a RADIUS client ·································································································································· 48
Displaying and maintaining AAA ································································································································ 48
AAA configuration examples ········································································································································ 49
AAA for Telnet users by an HWTACACS server ······························································································· 49
AAA for Telnet users by separate servers ··········································································································· 50
Authentication/authorization for SSH/Telnet users by a RADIUS server ························································ 51
AAA for portal users by a RADIUS server ·········································································································· 55
AAA for 802.1X users by a RADIUS server ······································································································· 64
Level switching authentication for Telnet users by an HWTACACS server ····················································· 70
RADIUS authentication and authorization for Telnet users by a switch ··························································· 73
Troubleshooting AAA ···················································································································································· 75
Troubleshooting RADIUS ······································································································································· 75
Troubleshooting HWTACACS ······························································································································ 76
802.1X fundamentals ················································································································································ 77
802.1X architecture ······················································································································································· 77
Controlled/uncontrolled port and port authorization status ······················································································ 77
802.1X-related protocols ·············································································································································· 78
Packet formats ························································································································································ 79
EAP over RADIUS ·················································································································································· 80
Initiating 802.1X authentication ··································································································································· 80
802.1X client as the initiator ································································································································ 80
i
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents