HP Cloud Network Manager Software manual Authentication, Containment methods

Page 46

Containment methods

You can enable wired and wireless containments to prevent unauthorized stations from connecting to your Cloud Network Manager network.

Cloud Network Manager supports the following types of containment mechanisms:

Wired containment — When enabled, APs generate ARP packets on the wired network to contain wireless attacks.

Wireless containment — When enabled, the system attempts to disconnect all clients that are connected or attempting to connect to the identified AP.

n None — Disables all the containment mechanisms.

n Deauthenticate only — With deauthentication containment, the AP or client is contained by disrupting the client association on the wireless interface.

n Tarpit containment — With tarpit containment, the AP is contained by luring clients that are attempting to associate with it to a tarpit. The tarpit can be on the same channel or a different channel as the AP being contained.

Authentication

This section provides the following information:

Understanding authentication methods on page 46

Supported authentication servers on page 48

Configuring authentication servers on page 49

Configuring 802.1X authentication for a network profile on page 52

Configuring MAC authentication for a network profile on page 53

Configuring MAC authentication with 802.1X authentication on page 53

Configuring MAC authentication with captive portal authentication on page 54

Configuring WISPr authentication on page 54

Blacklisting clients on page 55

Understanding authentication methods

Authentication is a process of identifying a user through a valid username and password. Clients can also be authenticated based on their MAC addresses.

The following authentication methods are supported in Cloud Network Manager:

802.1X authentication — 802.1X is a method for authenticating the identity of a user before providing network access to the user. Remote Authentication Dial In User Service (RADIUS) is a protocol that provides centralized authentication, authorization, and accounting management. For authentication purpose, the wireless client can associate to a network access server (NAS) or RADIUS client such as a wireless AP. The wireless client can pass data traffic only after successful 802.1X authentication. For more information on configuring an AP to use 802.1X authentication, see Configuring 802.1X authentication for a network profile on page 52.

MAC authentication — Media Access Control (MAC) authentication is used for authenticating devices based on their physical MAC addresses. MAC authentication requires that the MAC address of a machine matches a manually defined list of addresses. This authentication method is not recommended for scalable networks and the networks that require stringent security settings. For more information on configuring an AP to use MAC authentication, see Configuring MAC authentication for a network profile on page 53.

MAC authentication with 802.1X authentication —This authentication method has the following features:

HP Cloud Network Manager User Guide

Wireless configuration 46

Image 46
Contents HP Cloud Network Manager User Guide Document 5998-5742, edition 1 July AcknowledgmentsContents Wireless configuration Advanced configuration tasks Captive portal for guest access Reports Maintenance Related documents About this guideIntended audience ConventionsCloud Network Manager overview About Cloud Network ManagerSupported APs Cloud Network Manager UI Cloud Network Manager user interface Activating your Cloud Network Manager subscriptionsActivating your HP Cloud Network Manager account User interface Search Tabs Notifications Help Data paneSearch TabsHelp NotificationsData pane Support FeedbackOverview MonitoringData pane item Description Access points AP detailsSection Description ClientsRemote Console System pane Data pane itemEvent log Setting notification alerts Wireless network profiles Wireless configurationInitial AP configuration Importing existing configuration from APConfiguring Wlan settings Understanding wireless network profilesNetwork types Voice Guest DMO Channel Content FilteDisable Ssid UtilizationWithout Uplink MAX Clients Configuring Vlan settings for a Wlan Ssid profileCan be Used Local ProbeKEY Configuring security settings for a Wlan Ssid profileManagement KEY Management Termination AuthenticatioRoaming ServerConfiguring access rules for a Wlan Ssid profile Editing a Wlan Ssid profile General configuration tasksDeleting a Wlan Ssid profile Basic configuration tasks Modifying the AP nameConfiguring a preferred band Configuring VC IP addressConfiguring time zone Configuring an NTP serverConfiguring auto join mode Additional configuration tasksConfiguring VC Vlan Configuring LED displayPreventing local routing between clients Advanced configuration tasksDisabling inter-user bridging Enabling dynamic CPU managementConfiguring radio profiles manually for AP Configuring radio profiles for an APConfiguring Arrm assigned radio profiles for an AP Customizing AP parametersMode Description Configuring uplink Vlan for an APSelect Administrator assigned in 2.4 GHz and 5 GHz Band Obtaining IP addressAdvanced radio resource management Arrm overviewHP MotionAware Airtime fairness modeAP control Monitoring the network with Arrm Configuring Arrm on an APArrm metrics Calculating SLB ModeMotion Aware MA NeighborValid PowerCustomize ChannelsConfiguring radio settings for an AP Intrusion detection systemDetecting and classifying rogue APs OS fingerprintingOff Low Medium High Detection level Detection policyOff Low High Settings fieldProtection level Protection policy Understanding authentication methods AuthenticationContainment methods Wireless configuration External Radius server Supported authentication serversRadius server authentication with VSA Internal Radius serverAuthentication termination on AP Configuring authentication serversConfiguring an external server for authentication Retype Shared KEY TimeoutShared KEY Retry CountConfiguring dynamic Radius proxy parameters Click Save ServerConfiguring 802.1X authentication for a network profile Enabling dynamic Radius proxyConfiguring MAC authentication for a network profile Configuring MAC authentication with 802.1X authenticationConfiguring WISPr authentication Blacklisting clients manually Blacklisting clientsBlacklisting users dynamically Understanding captive portal Captive portal for guest accessConfiguring blacklist duration Session firewall based blacklistingWalled garden Configuring a Wlan Ssid for guest accessTypes of captive portal Select the Primary Usage as GuestMulticast Transmission Content FilteringInactivity Timeout Dynamic MulticastUplink MAX Clients Threshold Can be Used WithoutLocal Probe Request Configuring internal captive portal for guest network External captive portal profiles Configuring external captive portal for a guest networkSelect any one of the following types of authentication Creating a captive portal profileCaptive Portal URLUSE Https FailureSplash Configuring captive portal roles for an SsidRule Type TypeInternal Configuring walled garden accessExternal Configuring Dhcp scopes Dhcp configurationDisabling captive portal authentication Configuring local and local, L3 Dhcp scopesNET Mask VlanNetwork Excluded AddressConfiguring Dhcp server for client IP assignment ServicesConfiguring an AP for Rtls support Select Wireless Configuration Services RtlsBonjour support configuration Configuring OpenDNS credentialsBonjour support overview Bonjour support solution Bonjour support with Cloud Network ManagerBonjour support services Bonjour support featuresSelect Wireless Configuration Services Bonjour Support Integrating an AP with Palo Alto Networks firewall Configuring an AP for PAN integrationIntegration with Cloud Network Manager Configuring a Wi-Fi uplink profile Uplink configurationWi-Fi uplink Uplink interfacesConfiguring PPPoE uplink profile Ethernet uplinkSetting an uplink priority Uplink preferences and switchingEnforcing uplinks Mobility and client management Switching uplinks based on internet availabilityFrom PRE-EMPTION, select Enabled Layer-3 mobility overviewConfiguring L3-mobility Enterprise domain Configuring L3 mobility domainConfiguring enterprise domains Snmp and loggingSnmp parameters for AP Configuring SnmpConfiguring community string for Snmp Creating community strings for SNMPv1 and SNMPv2Configuring Snmp traps Configuring a syslog serverCreating community strings for SNMPv3 Select Wireless Configuration System Logging Configuring Tftp dump serverLogging level Description Reports Creating a reportDeleting a report Firmware MaintenanceSubscription keys Device management User managementAcronyms and abbreviations TerminologyAbbreviation Expansion Term GlossaryDefinition DST Term DefinitionEAP POE Through a wireless connection

Cloud Network Manager Software specifications

HP Cloud Network Manager is a robust software solution designed to simplify and enhance the management of network infrastructure in cloud environments. As organizations increasingly shift toward cloud computing, they require comprehensive tools to oversee complex network deployments. HP Cloud Network Manager rises to this challenge, offering a powerful suite of features aimed at optimizing performance, automating tasks, and ensuring reliable connectivity.

One of the main features of HP Cloud Network Manager is its intuitive dashboard, which provides users with real-time insights into network operations. This centralized interface allows administrators to monitor the status of various components, identify potential issues, and respond swiftly to anomalies. With advanced analytics capabilities, the software empowers users to make data-driven decisions that enhance network efficiency.

Another critical feature of this software is its automation capabilities. HP Cloud Network Manager simplifies routine network management tasks, such as configuration, provisioning, and software updates, allowing IT teams to focus on strategic initiatives rather than mundane maintenance. Automation reduces the risk of human error and accelerates deployment times, significantly increasing operational agility.

The software also supports multi-cloud environments, enabling organizations to manage their network resources across different cloud platforms seamlessly. This flexibility is essential for businesses that utilize various cloud providers and wish to maintain a unified network strategy. Coupled with its compatibility with open standards, HP Cloud Network Manager facilitates integration with existing IT ecosystems, ensuring a smooth transition to advanced cloud solutions.

Security is a top priority in today's digital landscape, and HP Cloud Network Manager includes integrated security features to protect network assets. It provides visibility into traffic patterns, helping to detect and mitigate potential threats before they become significant issues. Enhanced security protocols ensure that sensitive data remains protected during transit and at rest, aligning with compliance requirements.

Finally, HP Cloud Network Manager is built on cutting-edge technologies, including artificial intelligence and machine learning, which enable proactive network management. These technologies predict network behavior, assisting administrators in optimizing resources and anticipating potential challenges. As a result, organizations can achieve enhanced reliability and performance from their network infrastructure.

In summary, HP Cloud Network Manager is an essential tool for businesses looking to improve their cloud network management capabilities. With its powerful features, supportive technologies, and commitment to security, it stands out as a reliable solution for navigating the complexities of modern network environments.