HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 55

Configuring a NAS ID-VLAN binding, Displaying and maintaining AAA, AAA configuration examples

Page 55 highlights

Configuring a NAS ID-VLAN binding The access locations of users can be identified by their access VLANs. In application scenarios where identifying the access locations of users is a must, configure NAS ID-VLAN bindings on the switch. Then, when a user gets online, the switch obtains the NAS ID by the access VLAN of the user and sends the NAS ID to the RADIUS server through the NAS-identifier attribute. To configure a NAS ID-VLAN binding: Step 1. Enter system view. 2. Create a NAS ID profile and enter NAS ID profile view. 3. Configure a NAS ID-VLAN binding. Command system-view aaa nas-id profile profile-name nas-id nas-identifier bind vlan vlan-id Remarks N/A N/A By default, no NAS ID-VLAN binding exists. Displaying and maintaining AAA Task Display the configuration information of ISP domains. Display information about user connections . Command Remarks display domain [ isp-name ] [ | { begin | exclude | include } regular-expression ] Available in any view display connection [ access-type { dot1x | mac-authentication } | domain isp-name | interface interface-type interface-number | ip ip-address | mac mac-address | ucibindex ucib-index | user-name user-name | vlan vlan-id ] [ slot slot-number ] [ | { begin | exclude | include } regular-expression ] Available in any view AAA configuration examples AAA for Telnet users by an HWTACACS server Network requirements As shown in Figure 10, configure the switch to use the HWTACACS server to provide authentication, authorization, and accounting services for Telnet users. Set the shared keys for secure communication with the HWTACACS server to expert. Configure the switch to remove the domain name from a username before sending the username to the HWTACACS server. 45

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

45
Configuring a NAS ID-VLAN binding
The access locations of users can be identified by their access VLANs. In application scenarios where
identifying the access locations of users is a must, configure NAS ID-VLAN bindings on the switch. Then,
when a user gets online, the switch obtains the NAS ID by the access VLAN of the user and sends the
NAS ID to the RADIUS server through the NAS-identifier attribute.
To configure a NAS ID-VLAN binding:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a NAS ID profile and
enter NAS ID profile view.
aaa nas-id profile
profile-name
N/A
3.
Configure a NAS ID-VLAN
binding.
nas-id
nas-identifier
bind vlan
vlan-id
By default, no NAS ID-VLAN
binding exists.
Displaying and maintaining AAA
Task
Command
Remarks
Display the configuration
information of ISP domains.
display domain
[
isp-name
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display information about user
connections .
display
connection
[
access-type
{
dot1x
|
mac-authentication
} |
domain
isp-name
|
interface
interface-type interface-number
|
ip
ip-address
|
mac
mac-address
|
ucibindex
ucib-index
|
user-name
user-name
|
vlan
vlan-id
] [
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
AAA configuration examples
AAA for Telnet users by an HWTACACS server
Network requirements
As shown in
Figure 10
, configure the switch to use the HWTACACS server to provide authentication,
authorization, and accounting services for Telnet users.
Set the shared keys for secure communication with the HWTACACS server to
expert
. Configure the
switch to remove the domain name from a username before sending the username to the HWTACACS
server.