General Management Considerations
Enterasys NAC Controller Hardware Installation Guide 6-3
General Management Considerations
ThefollowingaregeneralNAC Controllermanagementconfigurationconsiderations:
•TheLayer3NACControllerispositionedinbetweentworoutersonthenetwork.Onlyone
VLAN/subnetspansbetweentheseroutersasshowninFigure 6‐2.ForLayer3NAC
Controllerconfiguration,alldatatraffic(non‐managementtraffic)traversingtheNAC
Controllerbetweenthe
upstreamrouterandthedownstreamroutermustbeuntagged.The
reasonforthisisthattheNACControllerdoesnotpreserveVLANtaggingfordatatraffic
traversingtheappliance,regardlessofwhetherin‐bandorout‐of‐bandmanagementis
configured.Theupstreamanddownstreamroutersmustbeconfiguredwith
routedinterfaces
forthisVLAN/subnetasshownbelowwithIPaddresses20.20.20.2/24and202020.1/24.
Figure 6-2 Layer 3 NAC Controller Positioning
•WhenusingIn‐Bandmanagement:
–TwoIPaddressesareassignedtotheNACControllerwhenconfiguredforin‐band
management;amanagementIPaddressfortheNACControllerEngineanda
managementIPaddressfor
theNACControllerPEP.
–TheNACControllerEngineIPaddressandNACControllerPEPIPaddresses,masks,and
gatewaymustbepartofthesamesubnetthatspanstheupstreamanddownstream
routers.
–NomanagementVLANIDisrequired.AllmanagementtrafficsourcedfromtheNAC
ControllerEngineandNACController
PEPegressestheupstreamanddownstreamports
oftheNACControlleruntaggedontotheVLAN thatspansthetworouters,showas
shownbelow.
–AremediationwebserverIPaddressisnotrequired.Theremediationwebserverisrun
offofthemanagementIPaddressoftheNACControllerEngine.
–Alldirectly
connectedmanagementandrouterIPaddressesonthissubnetmustbe
specifiedduringthesetupprocessinordertoestablishIPconnectivityinto thetopology.
SeeFigure 6‐5onpage 6‐5foradiagramonlayer3In‐Bandmanagement.SeeFigure 6‐3on
page 6‐4foradiagramonlayer
2In‐Bandmanagement.
•WhenusingOut‐Of‐Bandmanagement:
–ThreeIPaddressesareassignedtotheLayer3NACControllerwhenconfiguredfor
out‐of‐bandmanagement;amanagementIPaddressandremediationIPaddressforthe
NACControllerEngineandamanagementIPaddressfortheNACControllerPEP.