Ethernet 802.1X configuration – HP
In this topic, you will learn how to configure selected HP switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for wired Ethernet connections.
Important:
This guide provides general instructions for integrating Portnox Cloud with specific
third-party devices. While we aim to provide helpful examples for commonly used models, configurations may vary across
manufacturers, models, and environments. As a result, we cannot guarantee that these steps will work in every
scenario. For questions or issues related to RADIUS setup – which is an industry standard and not specific to
Portnox – or device-specific settings and troubleshooting, we recommend consulting the device manufacturer’s documentation
and contacting their support team. While Portnox Support is happy to assist where possible, please note that detailed
configuration of third-party devices is typically best handled by the manufacturer.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to
your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as
underlined italics.
HP ProCurve (generic)
In this section, you will learn how to configure the HP ProCurve switches to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Ethernet connections.
Warning:
This configuration might not work on all HP ProCurve models and firmware versions. To get the most
accurate and current configuration guidance on switch 802.1X configuration, we strongly recommend that you refer to the
documentation provided by HP on these topics for your particular device model and firmware version.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to
your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as
underlined italics.
Here is the entire example configuration for your convenience:
radius-server host 20.119.69.248 key rTHO9HEo9BcqfC9Yg0hHFelK6o0tH8N1 auth-port 10322 acct-port 10323
radius-server host 52.232.122.157 key fnSrSEHhXFZ5Rqpz756NJhkeVqIHTlPt auth-port 10476 acct-port 10477
#
aaa authentication port-access eap-radius
#
aaa port-access authenticator 1-4
aaa port-access authenticator 1-4 auth-vid 10
aaa port-access authenticator 1-4 client-limit 20
#
aaa port-access mac-based 5-8
aaa port-access mac-based 5-8 addr-limit 15
aaa port-access mac-based 5-8 auth-vid 20
aaa port-access mac-based 5-8 unauth-vid 30
#
aaa port-access 1-8 controlled-direction both
aaa port-access authenticator active
HP 5130 HPE Comware 7
In this section, you will learn how to configure the HP 5130 HPE Comware 7 switch to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Ethernet connections.
Warning:
We tested this configuration on HP 5130 HPE Comware 7 with firmware 7.1.045, release 3113P05. This
configuration might not work on other HP Comware models and other firmware versions. To get the most accurate and
current configuration guidance on switch 802.1X configuration, we strongly recommend that you refer to the documentation
provided by HP on these topics for your particular device model and firmware version.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to
your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as
underlined italics.
Here is the entire example configuration for your convenience:
radius scheme portnox
primary authentication 20.119.69.248 10322 key cipher rTHO9HEo9BcqfC9Yg0hHFelK6o0tH8N1
primary accounting 20.119.69.248 10323 key cipher rTHO9HEo9BcqfC9Yg0hHFelK6o0tH8N1
secondary authentication 52.232.122.157 10476 key cipher fnSrSEHhXFZ5Rqpz756NJhkeVqIHTlPt
secondary accounting 52.232.122.157 10477 key cipher fnSrSEHhXFZ5Rqpz756NJhkeVqIHTlPt
accounting-on enable
user-name-format without-domain
domain default enable system
domain system
authentication lan-access radius-scheme portnox
authorization lan-access radius-scheme portnox
accounting lan-access radius-scheme portnox
dot1x
dot1x authentication-method eap
dot1x quiet-period
dot1x timer quiet-period 20
dot1x timer tx-period 10
mac-authentication
interface GigabitEthernet 0/1
stp edged-port
dot1x
undo dot1x handshake
undo dot1x multicast-trigger
dot1x mandatory-domain system
dot1x unicast-trigger
dot1x re-authenticate server-unreachable keep-online
mac-authentication
mac-authentication domain system
mac-authentication re-authenticate server-unreachable keep-online
mac-authentication re-authenticate
