Enterasys Networks 9034385 Plumbing Product User Manual


 
NAC Solution Components
1-6 Overview
ofsupportingauthenticationand/orauthorization.TheNACControllerisalsorequiredinIPSec
andSSLVPNdeployments.
TheNACControllerprovidesintegratedvulnerabilityassessmentserverfunctionalityand
supportsbothagentless(networkbased)andagentbasedassessment.(Aseparatelicenseis
requiredforintegratedassessment.)Italsosupportstheabilityto
connecttomultipleexternal
assessmentserversincludingNessusandLockdownEnforcer.
TheNACControllercanbeconfiguredinoneoftwomodesofoperation:Layer2orLayer3.The
modeofoperationcontrolshowconnectingendsystemsaredetectedbytheNACControlleron
thenetworkandisselectedbased
onwheretheNACControllerispositionedinthenetworkin
relationtotheseendsystems.IftheNACControllerispositionedbeforethefirstroutedboundary
forconnectingendsystems,closertotheaccessedgeofthenetwork,theLayer2NACController
modeisutilized.Inthismode
ofoperation,theNACControllerdetectsconnectingendsystems
onthenetworkbyreceivingtrafficfromanewMACaddress.IftheNACControllerispositioned
afterthefirstroutedboundarydeeperinsidethenetwork,theLayer3NACControllermodeis
utilized.Inthismodeofoperation,theNACController
detectsconnectingendsystemsonthe
networkbyreceivingtrafficfromanewIPaddress.WiththeNACControllersupportingboth
Layer2andLayer3modesofoperation,theNACControllercanbestrategicallypositionedinthe
networktopologytoachievethedesiredlevelofscalabilityandsecurity.
TheNAC
Controllerisavailableintwomodels:
•2S408225SYS‐24Port10/100/1000NACControllersupportsupto2000concurrentend
systems.
7S428019SYS‐18PortSFPNACControllersupportsupto2000concurrentendsystems.