EasyManuals Logo

HP ProCurve 5406zl Access Security Guide

HP ProCurve 5406zl
390 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #151 background imageLoading...
Page #151 background image
RADIUS Authentication and Accounting
General RADIUS Setup Procedure
General RADIUS Setup Procedure
Preparation:
1. Configure one to three RADIUS servers to support the switch. (That is,
one primary server and one or two backups.) Refer to the documentation
provided with the RADIUS server application.
2. Before configuring the switch, collect the information outlined below.
Table 6-1. Preparation for Configuring RADIUS on the Switch
•- Determine the access methods (console, Telnet, Port-Access (802.1X), web browser interface and/or SSH) for which
you want RADIUS as the primary authentication method. Consider both Operator (login) and Manager (enable) levels,
as well as which secondary authentication methods to use (local or none) if the RADIUS authentication fails or does
not respond.
Console access requires
Local as secondary
method to prevent lockout
if the primary RADIUS
access fails due to loss of
RADIUS server access or
other problems with the
server.
Note: The Webui access
task shown in this figure is
available only on the
switches covered in this
guide.
Figure 6-1. Example of Possible RADIUS Access Assignments
•- Determine the IP address(es) of the RADIUS server(s) you want to support the switch. (You can configure the switch
for up to three RADIUS servers.)
•- If you need to replace the default UDP destination port (1812) the switch uses for authentication requests to a specific
RADIUS server, select it before beginning the configuration process.
•- If you need to replace the default UDP destination port (1813) the switch uses for accounting requests to a specific
Radius server, select it before beginning the configuration process.
•- Determine whether you can use one, global encryption key for all RADIUS servers or if unique keys will be required
for specific servers. With multiple RADIUS servers, if one key applies to two or more of these servers, then you can
configure this key as the global encryption key. For any server whose key differs from the global key you are using,
you must configure that key in the same command that you use to designate that server’s IP address to the switch.
•- Determine an acceptable timeout period for the switch to wait for a server to respond to a request. ProCurve
recommends that you begin with the default (five seconds).
6-7

Table of Contents

Other manuals for HP ProCurve 5406zl

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve 5406zl and is the answer not in the manual?

HP ProCurve 5406zl Specifications

General IconGeneral
Product NameHP ProCurve 5406zl
CategorySwitch
LayerLayer 3
Operating Temperature32°F to 131°F (0°C to 55°C)
Operating Humidity15% to 95% non-condensing
ManagementSNMP, CLI
Power SupplyRedundant power supplies (optional)
Memory128 MB flash, 512 MB SDRAM

Related product manuals