HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 67

Verifying the configuration, Enable 802.1X for port GigabitEthernet 1/0/1.

Page 67 highlights

# Configure bbb as the default ISP domain for all users. Then, if a user enters a username without any ISP domain at login, the authentication and accounting methods of the default domain is used for the user. [Switch] domain default enable bbb 3. Configure 802.1X authentication: # Enable 802.1X globally. [Switch] dot1x # Enable 802.1X for port GigabitEthernet 1/0/1. [Switch] interface gigabitethernet 1/0/1 [Switch-GigabitEthernet1/0/1] dot1x [Switch-GigabitEthernet1/0/1] quit # Configure the access control method. (Optional. The default setting meets the requirement.) [Switch] dot1x port-method macbased interface gigabitethernet 1/0/1 Verifying the configuration When you use HP iNode client, no advanced authentication options are required, and the user can pass authentication after entering username dot1x@bbb and the correct password in the client property page. If the 802.1X client of Windows XP is used, select the Enable IEEE 802.1X authentication for this network option and select MD5-Challenge as the EAP type on the Authentication tab of the network connection properties window. The user passes authentication after entering the correct username and password in the pop-up authentication page. After the user passes authentication, the server assigns the port connecting the client to VLAN 4. Use the display connect command to view the connection information on the switch. [Switch] display connection Slot: 1 Index=22 , Username=dot1x@bbb IP=192.168.1.58 IPv6=N/A MAC=0015-e9a6-7cfe Total 1 connection(s) matched on slot 1. Total 1 connection(s) matched. # View the information of the specified connection on the switch. [Switch] display connection ucibindex 22 Slot: 1 Index=22 , Username=dot1x@bbb IP=192.168.1.58 IPv6=N/A MAC=0015-e9a6-7cfe Access=8021X ,AuthMethod=CHAP Port Type=Ethernet,Port Name=GigabitEthernet1/0/1 Initial VLAN=2, Authorization VLAN=4 ACL Group=Disable User Profile=N/A CAR=Disable Priority=Disable Start=2011-04-26 19:41:12 ,Current=2011-04-26 19:41:25 ,Online=00h00m14s 57

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

57
# Configure
bbb
as the default ISP domain for all users. Then, if a user enters a username without
any ISP domain at login, the authentication and accounting methods of the default domain is used
for the user.
[Switch] domain default enable bbb
3.
Configure 802.1X authentication:
# Enable 802.1X globally.
[Switch] dot1x
# Enable 802.1X for port GigabitEthernet 1/0/1.
[Switch] interface gigabitethernet 1/0/1
[Switch-GigabitEthernet1/0/1] dot1x
[Switch-GigabitEthernet1/0/1] quit
# Configure the access control method. (Optional. The default setting meets the requirement.)
[Switch] dot1x port-method macbased interface gigabitethernet 1/0/1
Verifying the configuration
When you use HP iNode client, no advanced authentication options are required, and the user can pass
authentication after entering username
dot1x@bbb
and the correct password in the client property
page.
If the 802.1X client of Windows XP is used, select the
Enable IEEE 802.1X authentication for this network
option and select
MD5-Challenge
as the EAP type on the
Authentication
tab of the network connection
properties window. The user passes authentication after entering the correct username and password in
the pop-up authentication page.
After the user passes authentication, the server assigns the port connecting the client to VLAN 4.
Use the
display connect
command to view the connection information on the switch.
[Switch] display connection
Slot:
1
Index=22
, Username=dot1x@bbb
IP=192.168.1.58
IPv6=N/A
MAC=0015-e9a6-7cfe
Total 1 connection(s) matched on slot 1.
Total 1 connection(s) matched.
# View the information of the specified connection on the switch.
[Switch] display connection ucibindex 22
Slot:
1
Index=22
, Username=dot1x@bbb
IP=192.168.1.58
IPv6=N/A
MAC=0015-e9a6-7cfe
Access=8021X
,AuthMethod=CHAP
Port Type=Ethernet,Port Name=GigabitEthernet1/0/1
Initial VLAN=2, Authorization VLAN=4
ACL Group=Disable
User Profile=N/A
CAR=Disable
Priority=Disable
Start=2011-04-26 19:41:12 ,Current=2011-04-26 19:41:25 ,Online=00h00m14s