HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
Table of Contents
13 Securing LAN Access With EAP.............................................................................................159
Overview...........................................................................................................................159
The Secure LAN Advisor............................................................................................159
Preparing Your LAN ........................................................................................................160
Determining the EAP Authentication Method to Use......................................................161
Securing WLANs with the HP-UX AAA Server..............................................................164
Digital Certificate Administration....................................................................................164
Using the “Self-Signed” Digital Certificates................................................................165
Installing Your Own Digital Certificates and Keys.....................................................166
Installing Server Certificates and Keys..................................................................166
Installing Client Certificates and Keys...................................................................167
Defining Certificate Locations on the HP-UX AAA Server...................................167
14 Managing Sessions...............................................................................................................169
Session Logs......................................................................................................................169
Displaying Session Attributes.....................................................................................169
Stopping a Session.......................................................................................................170
Session Limits...................................................................................................................170
Setting Limits on a User-by-User Basis.......................................................................171
Setting Timeout Values..........................................................................................171
Establishing a Filter................................................................................................171
Limiting Access Points (NAS-Port, NAS-ID, Calling-Station ID, and others).......171
Denying Access (Called-Station-ID and others)....................................................172
Limiting Simultaneous Sessions............................................................................172
Setting Limits for Users on a Global Basis..................................................................173
Setting Limits for All User Profiles Grouped by Realms.......................................173
15 Assigning IP Addresses..........................................................................................................174
Assigning Static IP Addresses..........................................................................................174
To Assign a Static IP (IPv4) Address to a Profile in Flat Files.....................................174
To Assign a Static IPv6 Address to a Profile in Flat Files............................................175
To Assign Static Traditional IP (IPv4) Addresses to a User Profile in an LDAP LDIF
File...............................................................................................................................177
To Assign Static IPv6 Addresses to a User Profile in an LDAP LDIF File..................178
Assigning Dynamic IP Addresses Using DHCP..............................................................178
16 OATH Standards-Based OTP Authentication.............................................................................179
OTP and OATH Overview................................................................................................179
HP-UX AAA Server and OATH Support.........................................................................180
Supported OTP Functions for RADIUS Standard Password (PAP) and MS-CHAP v2....182
Components Required to Configure OTP Authentication...............................................182
Configuring OTP Authentication on the HP-UX AAA Server ........................................183
OTP Authentication Configuration Flowchart............................................................183
154 Table of Contents