Designing Access Controls

Lay Out the Network

Table 3-114. Network Access Control Capabilities of ProCurve Edge Switches

Switch Series

MAC-Auth

Web-Auth

802.1X

Dynamic VLAN

Dynamic ACLs

 

 

 

 

Assignment

 

 

 

 

 

 

 

5400zl

X

X

X

X

X

5300xl

X

X

X

X

X

4200vl

X

X

X

X

 

4100gl

 

 

X

X

 

3500yl

X

X

X

X

X

3400cl

X

X

X

X

 

2900

X

X

X

X

 

2810

X

X

X

X

 

2800

X

X

X

X

 

2600

X

X

X

X

 

2510

 

 

X

X

 

2500

local only

 

X

X

 

1800

 

 

 

 

 

1700

 

 

 

 

 

 

 

 

 

 

 

Private Wireless Zone

The private wireless zone is a wireless network designed for delivering employees the resources they need no matter where they are or how they connect to the network. As with the public wireless zone, endpoints are typically laptops and PDAs that connect wirelessly to APs or RPs. The private wireless zone might blanket your entire organization, or it might include corporate meeting rooms in locations that are not often accessible to guest users.

Because this zone enables greater access to resources, it must provide greater security with strong authentication and encryption.

Table 3-115. Private Wireless Zone Policies

Zone

Access Control

EI Deployment

Testing Method

Authentication

Encryption

 

Method

 

 

Protocol

 

 

 

 

 

 

 

Private wireless

802.1X

802.1X

NAC EI agent

PEAP-

WPA/WPA2

 

 

 

 

MS-CHAPv2

 

 

 

 

 

 

 

3-142