HP 10500 Series Configuration Manual page 6

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Specifying the NAS-Port-ID for an interface ····································································································· 137
Specifying a NAS ID profile for an interface ··································································································· 137
Specifying a source IP address for outgoing portal packets ··················································································· 138
Specifying an auto redirection URL for authenticated portal users ········································································· 138
Configuring portal detection functions ······················································································································· 139
Configuring the portal server detection function ······························································································ 139
Configuring portal user information synchronization ······················································································ 140
Logging off portal users ··············································································································································· 141
Displaying and maintaining portal ···························································································································· 141
Portal configuration examples ···································································································································· 142
Configuring direct portal authentication ··········································································································· 142
Configuring re-DHCP portal authentication ······································································································ 147
Configuring cross-subnet portal authentication ································································································ 149
Configuring direct portal authentication with extended functions·································································· 151
Configuring re-DHCP portal authentication with extended functions ···························································· 153
Configuring cross-subnet portal authentication with extended functions ······················································· 155
Configuring portal server detection and portal user information synchronization ······································· 157
Cross-subnet portal authentication across VPNs ······························································································ 163
Troubleshooting portal ················································································································································· 165
Inconsistent keys on the access device and the portal server ········································································· 165
Incorrect server port number on the access device ·························································································· 165
Configuring port security ········································································································································ 166
Port security features ···················································································································································· 166
Port security modes ······················································································································································ 166
Working with guest VLAN and Auth-Fail VLAN ······································································································· 169
Configuration task list ·················································································································································· 169
Enabling port security ·················································································································································· 170
Setting port security's limit on the number of MAC addresses on a port······························································· 170
Setting the port security mode ···································································································································· 171
Configuration prerequisites ································································································································ 171
Configuration procedure ···································································································································· 171
Configuring port security features ······························································································································ 171
Configuring NTK ················································································································································· 172
Configuring intrusion protection ························································································································ 172
Enabling port security traps ································································································································ 173
Configuring secure MAC addresses ·························································································································· 173
Configuration prerequisites ································································································································ 174
Configuration procedure ···································································································································· 174
Ignoring authorization information from the server ·································································································· 175
Displaying and maintaining port security ·················································································································· 175
Port security configuration examples ························································································································· 176
Configuring the autoLearn mode ······················································································································· 176
Configuring the userLoginWithOUI mode ········································································································ 178
Configuring the macAddressElseUserLoginSecure mode ················································································ 183
Troubleshooting port security ······································································································································ 185
Cannot set the port security mode ····················································································································· 186
Cannot configure secure MAC addresses ········································································································ 186
Cannot change port security mode when a user is online ·············································································· 186
Configuring a user profile ······································································································································ 188
User profile configuration task list ······························································································································ 188
Creating a user profile ················································································································································ 188
Applying a QoS policy ··············································································································································· 189
Enabling a user profile ················································································································································ 189
iv
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Advertisement

Table of Contents
loading

Table of Contents