<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ProCurve 2910al -- can't set port-access credentials in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670276#M23385</link>
    <description>Hi,&lt;BR /&gt;I've got a new ProCurve 2910al-48G here and I'm currently playing around a bit with its AAA (802.1X) features. &lt;BR /&gt;&lt;BR /&gt;In the 'Access Security Guide' (which I got from &lt;BR /&gt;&lt;A href="http://cdn.procurve.com/training/Manuals/2910-ASG-Feb09-W_14_03.pdf" target="_blank"&gt;http://cdn.procurve.com/training/Manuals/2910-ASG-Feb09-W_14_03.pdf&lt;/A&gt; ) it says that I can -- and I should -- set a port-access username and password pair by doing somthing like that:&lt;BR /&gt;&lt;BR /&gt;swtswitch01(config)# password port-access user-name tom password123&lt;BR /&gt;Invalid input: port-access&lt;BR /&gt;swtswitch01(config)#&lt;BR /&gt;&lt;BR /&gt;But as you can see the switch replies "Invalid input". Looking a bit closer at the 'password' command I can see that 'operator', 'manager', 'all' are allowed for the first argument but not port-access as is described in the manual.&lt;BR /&gt;&lt;BR /&gt;I suspect I'm missing something but I can't find out what it is...&lt;BR /&gt;&lt;BR /&gt;Might this feature have been removed in the current Firmware-Release (I'm just trying to do local auth first for the sake of simplicity before setting it all up using FreeRADIUS)?&lt;BR /&gt;From 'show flash' I get&lt;BR /&gt;Primary Image   : 8482560   11/05/09 W.14.38 &lt;BR /&gt;Secondary Image : 8482560   11/05/09 W.14.38 &lt;BR /&gt;Boot Rom Version: W.14.04&lt;BR /&gt;&lt;BR /&gt;Any ideas?&lt;BR /&gt;Thanks in advance!&lt;BR /&gt; Tom</description>
    <pubDate>Wed, 04 Aug 2010 13:00:42 GMT</pubDate>
    <dc:creator>Thomas Wunder</dc:creator>
    <dc:date>2010-08-04T13:00:42Z</dc:date>
    <item>
      <title>ProCurve 2910al -- can't set port-access credentials</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670276#M23385</link>
      <description>Hi,&lt;BR /&gt;I've got a new ProCurve 2910al-48G here and I'm currently playing around a bit with its AAA (802.1X) features. &lt;BR /&gt;&lt;BR /&gt;In the 'Access Security Guide' (which I got from &lt;BR /&gt;&lt;A href="http://cdn.procurve.com/training/Manuals/2910-ASG-Feb09-W_14_03.pdf" target="_blank"&gt;http://cdn.procurve.com/training/Manuals/2910-ASG-Feb09-W_14_03.pdf&lt;/A&gt; ) it says that I can -- and I should -- set a port-access username and password pair by doing somthing like that:&lt;BR /&gt;&lt;BR /&gt;swtswitch01(config)# password port-access user-name tom password123&lt;BR /&gt;Invalid input: port-access&lt;BR /&gt;swtswitch01(config)#&lt;BR /&gt;&lt;BR /&gt;But as you can see the switch replies "Invalid input". Looking a bit closer at the 'password' command I can see that 'operator', 'manager', 'all' are allowed for the first argument but not port-access as is described in the manual.&lt;BR /&gt;&lt;BR /&gt;I suspect I'm missing something but I can't find out what it is...&lt;BR /&gt;&lt;BR /&gt;Might this feature have been removed in the current Firmware-Release (I'm just trying to do local auth first for the sake of simplicity before setting it all up using FreeRADIUS)?&lt;BR /&gt;From 'show flash' I get&lt;BR /&gt;Primary Image   : 8482560   11/05/09 W.14.38 &lt;BR /&gt;Secondary Image : 8482560   11/05/09 W.14.38 &lt;BR /&gt;Boot Rom Version: W.14.04&lt;BR /&gt;&lt;BR /&gt;Any ideas?&lt;BR /&gt;Thanks in advance!&lt;BR /&gt; Tom</description>
      <pubDate>Wed, 04 Aug 2010 13:00:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670276#M23385</guid>
      <dc:creator>Thomas Wunder</dc:creator>
      <dc:date>2010-08-04T13:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve 2910al -- can't set port-access credentials</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670277#M23386</link>
      <description>I guess I should mention that the example command was on page 455+456 (12-16/12-17)</description>
      <pubDate>Wed, 04 Aug 2010 13:46:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670277#M23386</guid>
      <dc:creator>Thomas Wunder</dc:creator>
      <dc:date>2010-08-04T13:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve 2910al -- can't set port-access credentials</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670278#M23387</link>
      <description>Hi Thomas &lt;BR /&gt;&lt;BR /&gt;I am not exactly sure what you want to achieve, but if you want to set up 802.1x for clients connecting to the switch you will need a radius server. &lt;BR /&gt;&lt;BR /&gt;The switch doesn't have any internal radius.&lt;BR /&gt;&lt;BR /&gt;You might be confusing with the Port supplicant feature. Basically this is to configure a switch port with credentials to authenticate to another switch. &lt;BR /&gt;So basically a switch authenticating against another switch. &lt;BR /&gt;&lt;BR /&gt;For standard 802.1x port authenticator, following the configuration guide from page 459 in the PDF you are lining too. &lt;BR /&gt;&lt;BR /&gt;But i am afraid you will need a radius server to test 802.1x&lt;BR /&gt;&lt;BR /&gt;Tore</description>
      <pubDate>Wed, 04 Aug 2010 13:59:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670278#M23387</guid>
      <dc:creator>Tore Valberg</dc:creator>
      <dc:date>2010-08-04T13:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve 2910al -- can't set port-access credentials</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670279#M23388</link>
      <description>Hi Again&lt;BR /&gt;&lt;BR /&gt;I can see the commands you are referring to in the manual. &lt;BR /&gt;&lt;BR /&gt;It looks like the manual is a bit outdated indeed. &lt;BR /&gt;&lt;BR /&gt;Tore</description>
      <pubDate>Wed, 04 Aug 2010 14:05:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670279#M23388</guid>
      <dc:creator>Tore Valberg</dc:creator>
      <dc:date>2010-08-04T14:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve 2910al -- can't set port-access credentials</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670280#M23389</link>
      <description>Hi Tore,&lt;BR /&gt;first of all thanks for your quick answer!&lt;BR /&gt;&lt;BR /&gt;There's still a thing I don't really understand. On page 12-26 it says:&lt;BR /&gt;&lt;BR /&gt;# aaa authentication port-access &lt;CHAP-RADIUS&gt;&lt;BR /&gt;&lt;BR /&gt;Configures local, chap-radius (MD5), or eap-radius as the primary password authentication method for port-access.&lt;BR /&gt;&lt;BR /&gt;And indeed the 'aaa authentication port-access local' works. (Also the switch gives me amongst other options&lt;BR /&gt;' local        Use local switch user/password database.' amongst other options when i do &lt;BR /&gt;'aaa authentication port-access ?'&lt;BR /&gt;&lt;BR /&gt;So why can I configure the switch to use the local user/password database for 802.1X authentication while it is impossible to set a username password to be used? That's a bit strange isn't it? Did developers simply forget to remove that option or does it simply use the operator/manager user for 802.1X authentication? If the latter one is the case which are the usernames that should be used by a supplicant (I've already tried 'operator' and 'manager' with the according passwords but that didn't work out)?&lt;BR /&gt;&lt;BR /&gt;By the way is there an example configuration for the wpa_supplicant (from the Open1X project) to be used with the ProCurve switch for 802.1X auth? (I simply adapted the sample config from &lt;A href="https://help.ubuntu.com/community/Network802.1xAuthentication" target="_blank"&gt;https://help.ubuntu.com/community/Network802.1xAuthentication&lt;/A&gt; )&lt;/CHAP-RADIUS&gt;</description>
      <pubDate>Thu, 05 Aug 2010 10:54:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670280#M23389</guid>
      <dc:creator>Thomas Wunder</dc:creator>
      <dc:date>2010-08-05T10:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: ProCurve 2910al -- can't set port-access credentials</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670281#M23390</link>
      <description>Hi Thomas &lt;BR /&gt;&lt;BR /&gt;Sorry for the late reply. &lt;BR /&gt;&lt;BR /&gt;That is indeed a good point, i can also add the command but cant make use of it. &lt;BR /&gt;&lt;BR /&gt;It has been removed from teh latest documentation, but the command is still there. &lt;BR /&gt;&lt;BR /&gt;Looks like they forgot to remove it. Operator Manager login will not work. &lt;BR /&gt;&lt;BR /&gt;You might want to call HP regarding the command. &lt;BR /&gt;&lt;BR /&gt;Regarding the example configuration, on the switch you simply need to enable 802.1x. Rest is done on the radius. &lt;BR /&gt;&lt;BR /&gt;ProVision(config)# aaa authentication port-access eap-radius&lt;BR /&gt;ProVision(config)# radius-server host 10.0.100.111 key password&lt;BR /&gt;ProVision(config)# aaa port-access authenticator 13,17-18&lt;BR /&gt;ProVision(config)# aaa port-access authenticator active&lt;BR /&gt;&lt;BR /&gt;Alternatively you can set client limit and unauth and authorized vlans:&lt;BR /&gt;&lt;BR /&gt;ProVision(config)# aaa port-access authenticator 17-18 client-limit 3&lt;BR /&gt;ProVision(config)# aaa port-access authenticator 13,17-18 unauth-vid 99&lt;BR /&gt;ProVision(config)# aaa port-access authenticator 13,17-18 auth-vid 10&lt;BR /&gt;&lt;BR /&gt;Hope this helps</description>
      <pubDate>Mon, 16 Aug 2010 09:35:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/procurve-2910al-can-t-set-port-access-credentials/m-p/4670281#M23390</guid>
      <dc:creator>Tore Valberg</dc:creator>
      <dc:date>2010-08-16T09:35:12Z</dc:date>
    </item>
  </channel>
</rss>

