HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 3

Security Configuration Guide

Page 3 highlights

Contents Configuring AAA 1 AAA overview 1 RADIUS 2 HWTACACS 7 Domain-based user management 9 AAA for MPLS L3VPNs 10 Protocols and standards 10 RADIUS attributes 11 AAA configuration considerations and task list 14 Configuring AAA schemes 15 Configuring local users 15 Configuring RADIUS schemes 20 Configuring HWTACACS schemes 31 Configuring AAA methods for ISP domains 38 Configuration prerequisites 38 Creating an ISP domain 38 Configuring ISP domain attributes 39 Configuring AAA authentication methods for an ISP domain 40 Configuring AAA authorization methods for an ISP domain 42 Configuring AAA accounting methods for an ISP domain 43 Tearing down user connections 44 Configuring a NAS ID-VLAN binding 45 Displaying and maintaining AAA 45 AAA configuration examples 45 AAA for Telnet users by an HWTACACS server 45 AAA for Telnet users by separate servers 47 Authentication/authorization for SSH/Telnet users by a RADIUS server 48 AAA for 802.1X users by a RADIUS server 51 Level switching authentication for Telnet users by an HWTACACS server 58 RADIUS authentication and authorization for Telnet users by a switch 61 Troubleshooting AAA 63 Troubleshooting RADIUS 63 Troubleshooting HWTACACS 64 802.1X overview 65 802.1X architecture 65 Controlled/uncontrolled port and port authorization status 65 802.1X-related protocols 66 Packet formats 67 EAP over RADIUS 68 Initiating 802.1X authentication 68 802.1X client as the initiator 68 Access device as the initiator 69 802.1X authentication procedures 69 A comparison of EAP relay and EAP termination 70 EAP relay 70 EAP termination 73 Configuring 802.1X 74 HP implementation of 802.1X 74 i

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

i
Contents
Configuring AAA ························································································································································· 1
AAA overview ···································································································································································1
RADIUS ······································································································································································2
HWTACACS ·····························································································································································7
Domain-based user management ···························································································································9
AAA for MPLS L3VPNs ········································································································································· 10
Protocols and standards ······································································································································· 10
RADIUS attributes ·················································································································································· 11
AAA configuration considerations and task list ·········································································································· 14
Configuring AAA schemes ············································································································································ 15
Configuring local users ········································································································································· 15
Configuring RADIUS schemes ······························································································································ 20
Configuring HWTACACS schemes ····················································································································· 31
Configuring AAA methods for ISP domains ················································································································ 38
Configuration prerequisites ·································································································································· 38
Creating an ISP domain ······································································································································· 38
Configuring ISP domain attributes ······················································································································· 39
Configuring AAA authentication methods for an ISP domain ·········································································· 40
Configuring AAA authorization methods for an ISP domain ··········································································· 42
Configuring AAA accounting methods for an ISP domain ··············································································· 43
Tearing down user connections ···································································································································· 44
Configuring a NAS ID-VLAN binding ·························································································································· 45
Displaying and maintaining AAA ································································································································ 45
AAA configuration examples········································································································································ 45
AAA for Telnet users by an HWTACACS server ······························································································· 45
AAA for Telnet users by separate servers ··········································································································· 47
Authentication/authorization for SSH/Telnet users by a RADIUS server ························································ 48
AAA for 802.1X users by a RADIUS server ······································································································· 51
Level switching authentication for Telnet users by an HWTACACS server ····················································· 58
RADIUS authentication and authorization for Telnet users by a switch··························································· 61
Troubleshooting AAA ···················································································································································· 63
Troubleshooting RADIUS······································································································································· 63
Troubleshooting HWTACACS······························································································································ 64
802.1X overview ······················································································································································· 65
802.1X architecture ······················································································································································· 65
Controlled/uncontrolled port and port authorization status ······················································································ 65
802.1X-related protocols ·············································································································································· 66
Packet formats
························································································································································ 67
EAP over RADIUS ·················································································································································· 68
Initiating 802.1X authentication ··································································································································· 68
802.1X client as the initiator································································································································ 68
Access device as the initiator ······························································································································· 69
802.1X authentication procedures ······························································································································ 69
A comparison of EAP relay and EAP termination ······························································································ 70
EAP relay ································································································································································ 70
EAP termination ····················································································································································· 73
Configuring 802.1X ·················································································································································· 74
HP implementation of 802.1X ······································································································································ 74