beautypg.com

HP Identity Driven Manager Software Series User Manual

Page 119

background image

3-55

Using Identity Driven Manager

Configuring Auto-Allow OUIs

Figure 3-39. Network Access with Auto-Allow OUI

In the picture above, the following steps take place before a static device is allowed
network access:

1. Using the IDM client a user adds a MAC prefix/OUI to an Access Policy Group.

The OUI can be added to an existing Access Policy Group or a new Access
Policy Group can be created for the OUI. An OUI may contain 1 to 12 characters.

2. When a device is connected to a switch port configured for MAC-based authen-

tication, the RADIUS request packet is sent to the RADIUS Server. The
RADIUS server rejects the device because the user name (MAC address) is not
in the Active Directory.

3. This request is then forwarded to the IDM Agent for authorization.

4. The IDM Agent compares this user name (MAC address) against the list of

configured OUIs.