HP (Hewlett-Packard) 700wl Series Switch User Manual


 
Configuring Authentication
If the Identity Profile is not what you expected:
For users in the built-in database, the user may have been assigned to a different profile
than you expected.
If the user should match an Identity Profile based on a group or NT Domain name
returned from an external authentication service, the service may be returning a
different group name than you expected, or no matching Identity Profile has been
created to match the group or Domain.
There may be multiple Identity Profiles that this user could match, and it is matching
an Identity Profile in an earlier row in the Rights Assignment Table than you expected.
If the Access Policy is not what you expected, you should review your Rights Assignment Table
setup to determine whether you have multiple rows with the same Connection Profile and
Identity Profile but different Access Policies. If this is the case, the user will always match on
the first of these rows, and will never match on a later row. You should only have one row in
the Rights Assignment Table for each unique combination of Connection Profiles and Identity
Profiles.
If the
User Authentication Ends setting is not what you expect, check the Timeout setting in the
Access Policy.
The bottom portion of the results shows the actual XML that defines the rights the user would
receive (see Figure 5-21).
5-46 HP ProCurve Secure Access 700wl Series Management and Configuration Guide