EasyManua.ls Logo

HP ProCurve J8766A User Manual

HP ProCurve J8766A
124 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #102 background imageLoading...
Page #102 background image
96
Enhancements
Release L.11.08 Enhancements
Figure 1 shows an example of the show authentication command displaying authorized as the second-
ary authentication method for port-access, Web-auth access, and Mac-auth access. Since the config-
uration of authorized means no authentication will be performed and the client has unconditional
access to the network, the “Enable Primary” and “Enable Secondary” fields are not applicable (N/A).
Figure 4. Example of AAA Authentication Using Authorized for the Secondary Authentication Method
Specifying the MAC Address Format
The MAC address format command has been enhanced to allow upper-case letters to be used for the
hexadecimal numbers when indicating the MAC address in RADIUS packets for MAC-based authen-
tication.
Syntax: aaa port-access mac-based addr-format <no-delimiter | single-dash | multi-dash | multi-colon |
no-delimiter-uppercase | single-dash-uppercase | multi-dash-uppercase |
multi-colon-uppercase>
Specifies the MAC address format to be used in the RADIUS request message.
This format must match the format used to store the MAC addresses in the
RADIUS server. (Default: no-delimiter)
no-delimiter — specifies an aabbccddeeff format.
single-dash — specifies an aabbcc-ddeeff format.
multi-dash — specifies an aa-bb-cc-dd-ee-ff format.
multi-colon — specifies an aa:bb:cc:dd:ee:ff format.
no-delimiter-uppercasespecifies an AABBCCDDEEFF format.
single-dash-uppercase specifies an AABBCC-DDEEFF format
multi-dash-uppercasespecifies an AA-BB-CC-DD-EE-FF format
ProCurve(config)# show authentication
Status and Counters - Authentication Information
Login Attempts : 3
Respect Privilege : Disabled
| Login Login Enable Enable
Access Task | Primary Secondary Primary Secondary
----------- + ---------- ---------- ---------- ----------
Console | Local None Local None
Telnet | Local None Local None
Port-Access | Local Authorized N/A N/A
Webui | Local None Local None
SSH | Local None Local None
Web-Auth | ChapRadius Authorized N/A N/A
MAC-Auth | ChapRadius Authorized N/A N/A
The access methods
with secondary
authentication
configured as authorized
allows the client access
to the network even if the
RADIUS server is
unreachable.

Table of Contents

Other manuals for HP ProCurve J8766A

Questions and Answers:

HP ProCurve J8766A Specifications

General IconGeneral
BrandHP
ModelProCurve J8766A
CategorySoftware
LanguageEnglish

Summary

Software Management

Downloading Software to the Switch

Procedures for downloading switch software via TFTP or Xmodem transfer methods.

Enforcing Switch Security

Switch Management Access Security

Measures to secure access to switch status and configuration settings.

Local Manager Password

Setting a password to reduce unauthorized access via web or CLI interfaces.

Inbound Telnet Access and Web Browser Access

Securing remote access by using SSH and SSL/TLS protocols.

SNMP Access (Simple Network Management Protocol)

Controlling SNMP access to prevent unauthorized viewing or modification.

Network Access Security

Provisions to protect network access through the switch.

Access Control Lists (ACLs)

Using ACLs to permit or deny network traffic based on defined criteria.

Web and MAC Authentication

Port-based security using web or MAC address authentication for network access.

Secure Shell (SSH)

Using SSH for encrypted and authenticated remote access transactions.

802.1X Access Control

Port-based authentication using RADIUS for controlled network access.

Port Security, MAC Lockdown, MAC Lockout, and IP Lockdown

Device-based security features controlling port and IP access.

Enhancements

Uni-Directional Link Detection (UDLD)

Feature to detect and block unidirectional link failures for network stability.

DHCP Snooping Overview

Using DHCP snooping to mitigate DoS attacks by inspecting DHCP packets.

Spanning Tree Per-Port BPDU Filtering

Controls spanning-tree participation on a per-port basis.

Spanning Tree BPDU Protection

Security enhancement to disable ports receiving spoofed BPDUs.

Adding SNMPv3 Users With AES

Configuring SNMPv3 users with AES privacy for secure network management.

Dynamic ARP Protection

Protects against ARP poisoning by validating IP-to-MAC bindings.

Related product manuals