Triple Authentication Configuration Examples; Triple Authentication Basic Function Configuration Example - HP 3600 v2 Series Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Step
Configure MAC authentication.
2.
3.
Configure Layer-2 portal
authentication.

Triple authentication configuration examples

Triple authentication basic function configuration example

Network requirements
As shown in
authentication on the Layer-2 interface of the switch that connects to the terminals so that a terminal
passing one of the three authentication methods, 802.1X authentication, portal authentication, and MAC
authentication, can access the IP network.
Configure static IP addresses in network 192.168.1.0/24 for the terminals.
Use the remote RADIUS server to perform authentication, authorization, and accounting and
configure the switch to send usernames carrying no ISP domain names to the RADIUS server.
The local portal authentication server on the switch uses listening IP address 4.4.4.4. The switch
sends a default authentication page to the web user and forwards authentication data using HTTP.
Figure 70 Network diagram
802.1X client
Printer
Web user
Configuration procedure
Make sure that the terminals, the server, and the switch can reach each other.
The host of the web user must have a route to the listening IP address of the local portal server.
1.
Configure the RADIUS server, and make sure the authentication, authorization, and accounting
functions work normally. In this example, configure on the RADIUS server an 802.1X user (with
username userdot), a portal user (with username userpt), and a MAC authentication user (with a
username and password both being the MAC address of the printer 001588f80dd7).
2.
Configure portal authentication:
Figure
70, the terminals are connected to a switch to access the IP network. Configure triple
Vlan-int8
192.168.1.1/24
Eth1/0/1
Command
See
"Configuring MAC
authentication"
See
"Configuring portal
authentication"
RADIUS server
1.1.1.2/24
Vlan-int1
1.1.1.1
Switch
Vlan-int3
3.3.3.1
189
Remarks
authentication.
802.1X authentication must use
MAC-based access control.
HP does not recommend you
configure 802.1X guest VLANs
for triple authentication.
IP network

Advertisement

Table of Contents
loading

Table of Contents