Hi Group,
we try to configure a HP ProCurve 2650 Switch for a MAC-based authetication
and a dynamic membership of the involved switch port in a specific VLAN.
The authentication instance is a RADIUS server (freeRADIUS on a freeBSD
machine)
The 'access security guide'[1] describe in chapter 3 (Page 22):
-----------------------------------snip-----------------------------------
If you plan to use multiple VLANs with MAC Authentication, ensure that
these VLANs are configured on the switch and that the appropriate port
assignments have been made.
-----------------------------------snap-----------------------------------
We also read, that the VLANs should configured as static VLANs but we can't
find any information about the participation of each involved port in
designated VLANs (tagged, untagged). In my mind, every port should be in
'tagged' state on each configured VLAN. Up to now, i thought that 'tagged'
ports become only used for the uplink port to a another VLAN configured
switch. But in this specific case only 'tagged' condition make sense -> Is
this correct?
Anyway it won't work but... ;-)
....The second dissonance we had in our setup is the MD5 CHAP generated hash
who became transmitted from the switch to the RADIUS Server, if a Client is
connecting to the switch. The 'access security guide'[1] describes for MAC
based authentication we have to use the client MAC address for the username
as well as for the password...
--------------------------------------snip---------------------------------
The RADIUS server uses the device MAC address as the username and password,
and grants or denies network access in the same way that it does for
clients capable of interactive logons.
--------------------------------------snap---------------------------------
....but the transmitted hash - from the password? - is every time different
and doesn't match the manual generated hash from the password (MAC address)
by using the system MD5 genarator:
#>echo aabbccddeeff | md5 (aabbccddeeff is the client MAC address)
But maybe we misunderstand the output of this hash.
Can anybody help before we plunk the whole equipment ;-)
[1]
http://www.hp.com/rnd/support/manuals/2650_6108.htm
Bye Tom
--
"Der Retter der Welt ist ein Pinguin und Linus Torvalds ist sein Prophet "