Getting Started

Introduction

Introduction

This Access Security Guide is intended for use with the following switches:

HP Procurve Switch 4104GL

HP Procurve Switch 4108GL

Together, these two devices are termed the HP Procurve Series 4100GL

Switches.

Overview of Access Security Features

Local Manager and Operator passwords (page 1-1)

Control access and privileges for the CLI, menu, and web browser interface.

TACACS+ Authentication (page 2-1)

Uses an authentication application on a central server to allow or deny access to Series 4100GL switch.

RADIUS Authentication and Accounting (page 3-1)

Like TACACS+, uses an authentication application on a central server to allow or deny access to Series 4100GL switch. RADIUS also provides accounting services for sending data about user activity and system events to a RADIUS server.

Secure Shell (SSH) Authentication (page 4-1)

Provides encrypted paths for remote access to switch management functions.

Secure Sockets Layer (SSL) Authentication (page 5-1)

Provides encrypted paths for remote web access to the switch.

Port-Based Access Control (802.1x) (page 6-1)

On point-to-point connections, enables the switch to allow or deny traffic between a port and an 802.1x-aware device (supplicant) attempting to access the switch. Also enables the switch to operate as a supplicant for connections to other 802.1x-aware switches.

Port Security (page 7-1)

Enables a switch port to maintain a unique list of MAC addresses defining which specific devices are allowed to access the network through that port. Also enables a port to detect, prevent, and log access attempts by unauthorized devices.

Authorized IP Managers (page 8-1)

xii