802.1X User Authentication; Access Point Authentication - HP 530 Management Manual

Procurve wireless access point 530
Hide thumbs Also See for 530:
Table of Contents

Advertisement

Wireless Security Configuration
Wireless Security Overview
address as the MAC authentication password. To avoid this compatibility
issue, use the "radius" CLI command to configure the "mac-auth-password"
for the AP 530 to be consistent with the Access Point 520 shared-secret
password. For the CLI commands, see Section 9,
"MAC Address Authentication" on
.
page 9-72
MAC Authentication on the AP 530 includes the ability to lock out clients by
MAC address, and to force an already connected client or station to deauthen-
ticate.

802.1X User Authentication

802.1X user authentication can be implemented either by using a remote
authentication server, such as a RADIUS server, or by using the local built-in
RADIUS server on the access point itself. The user's credentials are exchanged
with the servers (both remote and local built-in) using a mechanism called
Extensible Authentication Protocol (EAP). EAP is a public-key encryption
system that ensures that only authorized network users can access the net-
work. In wireless communications using EAP, a user requests connection to
a WLAN through an access point, which then requests the identity of the user
and transmits that identity to an authentication server such as RADIUS. The
server asks the access point for proof of identity, which the access point gets
from the user and sends back to the server to complete the authentication.
The local built-in RADIUS server supports only one EAP type: PEAP-
MSCHAPv2. For remote server authentication, the access point serves as an
intermediate authenticator to transparently pass any EAP type to the remote
server as specified in RFC3748.
The AP 530 supports all EAP types tested by the Wi-Fi Alliance: TLS, TTLS,
PEAP-MSCHAPv2, PEAP1/GTC, and SIM. EAP types that do not provide key
management (like MD5) are not suitable for wireless networks. User 802.1X
authentication can be used with WEP, TKIP, and CCMP/AES encryption
ciphers.
It is possible to use a combination of both MAC authentication and 802.1X
authentication simultaneously on the same WLAN.

Access Point Authentication

ProCurve switches support port-access authentication which requires any
equipment plugged into the port to prove its authenticity through 802.1X
authentication, making their wireless networks less susceptible to rogue AP
7-7

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 530

Table of Contents