Enterasys Networks 2S4082-25-SYS Switch User Manual


 
General Management Considerations
6-4 Initializing the NAC Controller
–TheNACControllerEnginemanagementIPaddressisusedformanagementtraffic
generatedfromtheNACControllerEngine,andtheNACControllerEngineremediation
IPaddressusedtoruntheremediationwebserver.
–TheNACControllerEngineremediationIPaddress,mask,anddefaultgatewaymust
belongtothesubnetthatspans
thedownstreamandupstreamrouters.
–TheNACControllerEnginemanagementIPaddressalongwithamaskisassignedtothe
10/100Ethernetport.Therefore,the10/100Ethernetportmustbeconnectedintothe
topologywithaseparatephysicallinkontothemanagementVLAN.Nodefaultgateway
isassignedtothemanagement
IPaddress.
–TheNACControllerEnginemanagementIPaddressandNACControllerPEPIP
addresses,masks,andgatewaymustbepartofthesamesubnet,andnotonthesubnet
thatspanstheupstreamanddownstreamrouterswhichcarriesdatatraffic.
–AmanagementVLANIDmustbespecified.Allmanagementtraffic
sourcedfromthe
NACControllerPEPegressestheupstreamanddownstreamportsoftheNACController
taggedtothemanagementVLAN.Therefore,theupstreamanddownstreamrouters
mustbeconfiguredto802.1QVLANtrunkthemanagementVLANtotheNAC
Controller.
–TheNetSightmanagementserverIPaddressshouldbeconfiguredon
thesamesubnetas
theNACControllerEngineandNACControllerPEPIPaddresses.Otherwise,
managementtrafficsourcedfromtheNACControllerEngineandNACControllerPEP
willtraversethedataVLANonthewaytotheNetSightmanagementserver.
SeeFigure 64onpage 65foradiagramoflayer
2OutOfBandmanagementandFigure 66on
page 66foradiagramoflayer3OutOfBandmanagement
Figure 6-3 Layer 2 In-Band Management Topology