4-9
Configuring the RADIUS Server—Integrated with ProCurve Identity Driven Manager
Overview
■
If your NAC 800 loses connectivity to the LDAP server, it cannot authen-
ticate users.
Specifying multiple LDAP servers mitigates this disadvantage. See
Chapter 7: “Redundancy and Backup for RADIUS Services.”
Proxy RADIUS Server
The NAC 800 can proxy access requests to one or more RADIUS servers. The
NAC 800 acts as a RADIUS client to the proxy server, and the proxy server
looks up credentials and authenticates the user.
The NAC 800 can proxy all requests, or it can only proxy requests that meet
certain criteria, such as having a particular domain suffix.
Proxying requests is primarily intended for NAC 800s that implement endpoint
integrity. The existing RADIUS server handles authentication, and the NAC
800 handles the endpoint integrity.
However, you might choose the proxy option for a RADIUS-only NAC 800 in
this situation: you want to use IDM, but your existing RADIUS server does not
support the IDM agent. The NAC 800 will proxy authentication requests to the
existing server, which checks user credentials. When the NAC 800 receives an
access response from the proxy server, it will modify the response according
to policies configured through IDM.
To configure proxying, you must log in as root to the NAC 800’s (CS’s or ES’s)
command line and edit this file:
/etc/raddb/proxy.conf
. See “Configure
Authentication to a Proxy RADIUS Server” on page 4-30.
Advantages of using a proxy server for at least some requests include:
■
You do not have to duplicate user accounts already stored on another
RADIUS server.
■
You can gain the advantages of IDM in a network with existing RADIUS
servers that do not support the IDM agent.
Disadvantages of using the proxy server include:
■
The existing RADIUS server must still handle authentication requests, so
the NAC 800 does not relieve that burden.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......