Enterasys Networks 7S4280-19-SYS Computer Hardware User Manual


 
General Management Considerations
Enterasys NAC Controller Hardware Installation Guide 6-3
General Management Considerations
ThefollowingaregeneralNAC Controllermanagementconfigurationconsiderations:
•TheLayer3NACControllerispositionedinbetweentworoutersonthenetwork.Onlyone
VLAN/subnetspansbetweentheseroutersasshowninFigure 62.ForLayer3NAC
Controllerconfiguration,alldatatraffic(nonmanagementtraffic)traversingtheNAC
Controllerbetweenthe
upstreamrouterandthedownstreamroutermustbeuntagged.The
reasonforthisisthattheNACControllerdoesnotpreserveVLANtaggingfordatatraffic
traversingtheappliance,regardlessofwhetherinbandoroutofbandmanagementis
configured.Theupstreamanddownstreamroutersmustbeconfiguredwith
routedinterfaces
forthisVLAN/subnetasshownbelowwithIPaddresses20.20.20.2/24and202020.1/24.
Figure 6-2 Layer 3 NAC Controller Positioning
•WhenusingInBandmanagement:
–TwoIPaddressesareassignedtotheNACControllerwhenconfiguredforinband
management;amanagementIPaddressfortheNACControllerEngineanda
managementIPaddressfor
theNACControllerPEP.
–TheNACControllerEngineIPaddressandNACControllerPEPIPaddresses,masks,and
gatewaymustbepartofthesamesubnetthatspanstheupstreamanddownstream
routers.
–NomanagementVLANIDisrequired.AllmanagementtrafficsourcedfromtheNAC
ControllerEngineandNACController
PEPegressestheupstreamanddownstreamports
oftheNACControlleruntaggedontotheVLAN thatspansthetworouters,showas
shownbelow.
–AremediationwebserverIPaddressisnotrequired.Theremediationwebserverisrun
offofthemanagementIPaddressoftheNACControllerEngine.
–Alldirectly
connectedmanagementandrouterIPaddressesonthissubnetmustbe
specifiedduringthesetupprocessinordertoestablishIPconnectivityinto thetopology.
SeeFigure 65onpage 65foradiagramonlayer3InBandmanagement.SeeFigure 63on
page 64foradiagramonlayer
2InBandmanagement.
•WhenusingOutOfBandmanagement:
–ThreeIPaddressesareassignedtotheLayer3NACControllerwhenconfiguredfor
outofbandmanagement;amanagementIPaddressandremediationIPaddressforthe
NACControllerEngineandamanagementIPaddressfortheNACControllerPEP.