Enterasys Networks 7S4280-19-SYS Computer Hardware User Manual


 
Overview
6-2 Initializing the NAC Controller
TheportslocatedinthelowerrowsoftheNACControllerarereferredtoasʺdownstreamports,ʺ
andconnectdownlinktoinfrastructuredevicessuchasaccesslayerswitchesinthenetwork.The
twogigabitEthernetportslocatedatthetopoftheNACControllerarereferredtoasʺupstream
ports,ʺand
connectuplinktoupstreamdevicessuchascorerouters.The10/100Ethernetport
locatedatthetopoftheNACControllersupportsmanagementfunctionalitywithan
OutOfBandmanagementconfiguration,asexplainedbelow.SeeFigure 61forthelocationofthe
differentNAC Controllerporttypes.
Itisimportanttonote
thattheNACControllerappliancetransparentlybridgespacketsatlayer2
fromdownstreamportstoupstreamports,downstreamportstootherdownstreamports,
upstreamportstodownstreamports,andupstreamporttootherupstreamports. Therefore,itis
notnecessarytohavea1:1downstreamporttoupstreamportconfiguration
ontheNAC
Controller.Furthermore,thetrafficenforcementpointontheNACControllerisimplementedas
trafficingressedthedownstreamportsperMACaddressorIPaddressbeforethetrafficisbridged
throughtheNACControllertoanyotherport.Asaresultoftrafficsourcedfromanendsystem
being
appropriatelyfiltered(forexample:forwarded,discarded,containedtoaVLAN,or
prioritized)uponingresstotheNACControllerportbeforeitisbridged,theflowoftrafficfrom
eachdownstreamendsystem issecurelycontrolledtoallotherdevicesconnectedtoother
upstreamanddownstreamportsonthe NACController.
Figure 6-1 NAC Controller Ports
Figure 63throughFigure 66displaytheconfigurationtopologiesforthefourNAC Controller
installationtypes.Ineachcase,upstreamportsontheNACControllerconnecttothenetworkcore
inthedirectionofwheretheNetSightmanagementserverconnectstothenetwork,althoughitis
notnecessarytoconnecttheNetSight
managementserverupstreamfromtheNACController.
DownstreamportsontheNACControllerconnecttothenetworkedgewhereendsystemsare
connecting.
Note: Figure 6-1 displays a 2S4082-25-SYS, but NAC Controller ports are in the same
location on both systems.