Accounting Services; Radius-Administered Cos And Rate-Limiting; Terminology - HP ProCurve 6400cl Series Access Security Manual

Hide thumbs Also See for ProCurve 6400cl Series:
Table of Contents

Advertisement

RADIUS Authentication and Accounting

Terminology

6-4

Accounting Services

RADIUS accounting on the switch collects resource consumption data and
forwards it to the RADIUS server. This data can be used for trend analysis,
capacity planning, billing, auditing, and cost analysis.

RADIUS-Administered CoS and Rate-Limiting

The 3400cl and 6400cl switches, plus 5300xl switches running software release
E.09.xx or greater take advantage of vendor-specific attributes (VSAs) applied
in a RADIUS server to support these optional, RADIUS-assigned attributes:
802.1p (CoS) priority assignment to inbound traffic on the specified
port(s) (port-access authentication only)
Per-Port Rate-Limiting on a port with an active link to an authenti­
cated client (port-access authentication only)
For guidelines on configuring a RADIUS server to impose CoS and Rate-
Limiting settings for authenticated client sessions, refer to "Configuring a
RADIUS Server To Specify Per-Port CoS and Rate-Limiting Services" on page
6-21.

Terminology

CHAP (Challenge-Handshake Authentication Protocol): A challenge-
response authentication protocol that uses the Message Digest 5 (MD5)
hashing scheme to encrypt a response to a challenge from a RADIUS server.
CoS (Class of Service): Support for priority handling of packets traversing
the switch, based on the IEEE 802.1p priority carried by each packet. (For
more on this topic, refer to the "Overview" section in the "Quality of Service
(QoS)" chapter in the Advanced Traffic Management Guide for your switch.)
EAP (Extensible Authentication Protocol): A general PPP authentication
protocol that supports multiple authentication mechanisms. A specific
authentication mechanism is known as an EAP type, such as MD5-Challenge,
Generic Token Card, and TLS (Transport Level Security).
Host: See RADIUS Server.
NAS (Network Access Server): In this case, a ProCurve switch configured
for RADIUS security operation.

Advertisement

Table of Contents
loading

Table of Contents