HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 144

Configuring a user profile, Overview, User profile configuration task list

Page 144 highlights

Configuring a user profile Overview A user profile provides a configuration template to save predefined configurations, such as a Quality of Service (QoS) policy. Different user profiles are applicable to different application scenarios. The user profile supports working with 802.1X authentication. It is capable of restricting authenticated users' behaviors. After the authentication server verifies a user, it sends the device the name of the user profile that is associated with the user. Then the device applies the configurations in the user profile if the profile is enabled, and allows user access based on all valid configurations. If the user profile is not enabled, the device denies the user access. After the user logs out, the device automatically disables the configurations in the user profile, and the restrictions on the users are removed. Without user profiles, service applications are based on interface, VLAN, or globally, and a policy applies to any user that accesses the interface, or VLAN, or device. If a user moves between ports to access a device, to restrict the user behavior, you must remove the policy from the previous port and then configure the same policy on the port that the user uses. The configuration task is tedious and error prone. User profiles provide flexible user-based service applications because a user profile is associated with a target user. Every time the user accesses the device, the device automatically applies the configurations in the associated user profile. User profile configuration task list Task Creating a user profile Applying a QoS policy Enabling a user profile Remarks Required Required Required Creating a user profile Before you create a user profile, complete the following tasks: • Configure authentication parameters on the device. • Perform configurations on the client, the device, and the authentication server, for example, username, password, authentication scheme, domain, and binding a user profile with a user. To create a user profile: Step 1. Enter system view. 2. Create a user profile, and enter its view. Command system-view user-profile profile-name Remarks N/A You can use the command to enter the view of an existing user profile. 134

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

134
Configuring a user profile
Overview
A user profile provides a configuration template to save predefined configurations, such as a Quality of
Service (QoS) policy. Different user profiles are applicable to different application scenarios.
The user profile supports working with 802.1X authentication. It is capable of restricting authenticated
users' behaviors. After the authentication server verifies a user, it sends the device the name of the user
profile that is associated with the user. Then the device applies the configurations in the user profile if the
profile is enabled, and allows user access based on all valid configurations. If the user profile is not
enabled, the device denies the user access. After the user logs out, the device automatically disables the
configurations in the user profile, and the restrictions on the users are removed.
Without user profiles, service applications are based on interface, VLAN, or globally, and a policy
applies to any user that accesses the interface, or VLAN, or device. If a user moves between ports to
access a device, to restrict the user behavior, you must remove the policy from the previous port and then
configure the same policy on the port that the user uses. The configuration task is tedious and error prone.
User profiles provide flexible user-based service applications because a user profile is associated with a
target user. Every time the user accesses the device, the device automatically applies the configurations
in the associated user profile.
User profile configuration task list
Task
Remarks
Creating a user profile
Required
Applying a QoS policy
Required
Enabling a user profile
Required
Creating a user profile
Before you create a user profile, complete the following tasks:
Configure authentication parameters on the device.
Perform configurations on the client, the device, and the authentication server, for example,
username, password, authentication scheme, domain, and binding a user profile with a user.
To create a user profile:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a user profile,
and enter its view.
user-profile
profile-name
You can use the command to enter the view of
an existing user profile.