EasyManuals Logo

HP ProCurve 5406zl Access Security Guide

HP ProCurve 5406zl
390 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #91 background imageLoading...
Page #91 background image
Web and MAC Authentication
Overview
password, and grants or denies network access in the same way that it does
for clients capable of interactive logons. (The process does not use either a
client device configuration or a logon session.) MAC authentication is well-
suited for clients that are not capable of providing interactive logons, such as
telephones, printers, and wireless access points. Also, because most RADIUS
servers allow for authentication to depend on the source switch and port
through which the client connects to the network, you can use MAC-Auth to
“lock” a particular device to a specific switch and port.
Note 802.1X port-access and either Web authentication or MAC authentication can
be concurrently configured on the same port, with a maximum of 32 clients
allowed on the port. (The default is one client.)
Web authentication, MAC authentication, MAC lockdown, MAC lockout, and
port-security are mutually exclusive on a given port. Also, LACP must be
disabled on ports configured for any of these authentication methods.
Client Options
Web-Auth and MAC-Auth provide a port-based solution in which a port can
belong to one, untagged VLAN at a time. However, where all clients can
operate in the same VLAN, the switch allows up to 32 simultaneous clients per
port. (In applications where you want the switch to simultaneously support
multiple client sessions in different VLANs, design your system so that such
clients will use different switch ports.)
In the default configuration, the switch blocks access to clients that the
RADIUS server does not authenticate. However, you can configure an individ-
ual port to provide limited services to unauthorized clients by joining a
specified “unauthorized VLAN during sessions with such clients. The unau-
thorized VLAN assignment can be the same for all ports, or different, depend-
ing on the services and access you plan to allow for unauthenticated clients.
Access to an optional, unauthorized VID is configured in the switch when Web
and MAC Authentication are configured on a port.
General Features
Web and MAC Authentication on the 5400zl switches include the following:
4-3

Table of Contents

Other manuals for HP ProCurve 5406zl

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve 5406zl and is the answer not in the manual?

HP ProCurve 5406zl Specifications

General IconGeneral
Product NameHP ProCurve 5406zl
CategorySwitch
LayerLayer 3
Operating Temperature32°F to 131°F (0°C to 55°C)
Operating Humidity15% to 95% non-condensing
ManagementSNMP, CLI
Power SupplyRedundant power supplies (optional)
Memory128 MB flash, 512 MB SDRAM

Related product manuals