Ethernet 802.1X configuration – HP
In this topic, you will learn how to configure selected HP switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections.
Important:
This guide gives general instructions for integrating Portnox Cloud with specific
third-party devices. We try to provide useful examples for common models, but settings can differ between manufacturers,
models, and environments. Because of this, we cannot guarantee these steps will work in every case. For questions or
problems with RADIUS setup – which is an industry standard and not specific to Portnox – or with device-specific settings
and troubleshooting, we recommend checking the device manufacturer’s documentation and contacting their support team.
Portnox Support can help when possible, but detailed setup of third-party devices is usually best handled by the
manufacturer. We also recommend updating your NAS device firmware to the latest version, as old firmware can cause
issues.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to
your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as
underlined italics.
HP ProCurve (generic)
In this section, you will learn how to configure the HP ProCurve switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Ethernet connections.
Warning:
This configuration might not work on all HP ProCurve models and firmware versions. To get the most
accurate and current configuration guidance on switch 802.1X configuration, we strongly recommend that you refer to the
documentation provided by HP on these topics for your particular device model and firmware version.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to
your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as
underlined italics.
Here is the entire example configuration for your convenience:
radius-server host 20.119.69.248 key rTHO9HEo9BcqfC9Yg0hHFelK6o0tH8N1 auth-port 10322 acct-port 10323
radius-server host 52.232.122.157 key fnSrSEHhXFZ5Rqpz756NJhkeVqIHTlPt auth-port 10476 acct-port 10477
#
aaa authentication port-access eap-radius
#
aaa port-access authenticator 1-4
aaa port-access authenticator 1-4 auth-vid 10
aaa port-access authenticator 1-4 client-limit 20
#
aaa port-access mac-based 5-8
aaa port-access mac-based 5-8 addr-limit 15
aaa port-access mac-based 5-8 auth-vid 20
aaa port-access mac-based 5-8 unauth-vid 30
#
aaa port-access 1-8 controlled-direction both
aaa port-access authenticator active
HP 5130 HPE Comware 7
In this section, you will learn how to configure the HP 5130 HPE Comware 7 switch to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Ethernet connections.
Warning:
We tested this configuration on HP 5130 HPE Comware 7 with firmware 7.1.045, release 3113P05. This
configuration might not work on other HP Comware models and other firmware versions. To get the most accurate and
current configuration guidance on switch 802.1X configuration, we strongly recommend that you refer to the documentation
provided by HP on these topics for your particular device model and firmware version.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to
your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as
underlined italics.
Here is the entire example configuration for your convenience:
radius scheme portnox
primary authentication 20.119.69.248 10322 key cipher rTHO9HEo9BcqfC9Yg0hHFelK6o0tH8N1
primary accounting 20.119.69.248 10323 key cipher rTHO9HEo9BcqfC9Yg0hHFelK6o0tH8N1
secondary authentication 52.232.122.157 10476 key cipher fnSrSEHhXFZ5Rqpz756NJhkeVqIHTlPt
secondary accounting 52.232.122.157 10477 key cipher fnSrSEHhXFZ5Rqpz756NJhkeVqIHTlPt
accounting-on enable
user-name-format without-domain
domain default enable system
domain system
authentication lan-access radius-scheme portnox
authorization lan-access radius-scheme portnox
accounting lan-access radius-scheme portnox
dot1x
dot1x authentication-method eap
dot1x quiet-period
dot1x timer quiet-period 20
dot1x timer tx-period 10
mac-authentication
interface GigabitEthernet 0/1
stp edged-port
dot1x
undo dot1x handshake
undo dot1x multicast-trigger
dot1x mandatory-domain system
dot1x unicast-trigger
dot1x re-authenticate server-unreachable keep-online
mac-authentication
mac-authentication domain system
mac-authentication re-authenticate server-unreachable keep-online
mac-authentication re-authenticate
