Enterasys Networks 9034385 Plumbing Product User Manual


 
Survey the Network
Enterasys NAC Design Guide 4-3
ThenetworkshowninFigure 41below,illustratesthefollowingthreeexamplesofhowthe
intelligentedgecanbeimplementedinanetwork.
PolicyenabledEnterasysdevicesatthephysicaledgeofthenetwork.
TheSecureStackB2/B3,SecureStackC2/C3,andMatrixNseriesswitchesaretheintelligent
edgeofthenetwork
aswellasthephysicaledgeofthenetwork.Thesepolicyenableddevices
provideauthenticationandauthorizationviapolicyenforcementtotheconnectingend
systems.
•ThirdpartyswitchesthatsupportRFC3580withdynamicVLANassignmentatthe
physicaledgeofthenetwork.
RFC3580compliantswitches(Enterasysandthirdparty),
arealsopartoftheintelligentedge
ofthenetwork,becausetheyareabletoauthenticateandauthorizeconnectingendsystems
withaparticularlevelofnetworkaccess,usingdynamicVLANassignment.
•PolicyenabledEnterasysdevicesatthedistributionlayerofthenetwork,upstreamfrom
nonintelligentthirdpartydevices.
Theintelligent
edgeofthenetworkmayormaynotbethephysicaledgeofthenetworkwhere
endsystemsactuallyconnect.TheMatrixNseriesswitchinthedistributionlayerofthe
network,upstreamfromthenonintelligentthirdpartydevice,isalsoconsideredpartofthe
intelligentedgeofthe
network.ThisisbecausetheMatrixNseriesswitchcanindividually
authenticateanduniquelyallocatenetworkresourcesfortheendsystemsconnected
downstreamtothenonintelligentthirdpartyaccesslayerdevice.
Figure 4-1 Network with Intelligent Edge