4-10
Configuring the RADIUS Server—Integrated with ProCurve Identity Driven Manager
Overview
■
The EAP method must allow the username to be transmitted in plaintext.
IDM requires access to the username. If the proxy server and supplicant
always transmit the username in encrypted form, IDM cannot determine
the correct policy to apply.
For example, EAP-TTLS might exhibit this problem.
An example of an EAP method that works with proxying is Microsoft’s
implementation of PEAP.
■
If your NAC 800 loses connectivity to the proxy server, it cannot authen-
ticate users.
Specifying multiple proxy servers mitigates this disadvantage.
■
Manual configuration creates opportunities for errors.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......