Enterasys Networks 9034385 Plumbing Product User Manual


 
Out-of-Band NAC Design Procedures
5-20 Design Procedures
2. Determine the Number of NAC Gateways
ThenumberofNACGatewaystobedeployedonthenetworkisafunctionofthefollowing
parameters:
•ThenumberofSecurityDomainsconfiguredonthenetwork.
EachNACGatewayappliancemaybeassociatedtoonlyoneSecurityDomain.Therefore,the
numberofNACGatewaysdeployedonthenetworkwillbegreater
thanorequaltothe
numberofSecurityDomainsconfiguredinNACManager.Tosupportredundancyper
SecurityDomain,atleasttwoNACGatewaysmustbedeployedperSecurityDomain,as
discussedbelow.
•ThenumberofauthenticatingusersanddevicesthatareconnectedtoeachSecurityDomain.
EachNACGatewayappliance
hasthecapabilityofsupportingamaximumnumberof
authenticatingdevicesasshowninthefollowingtable:
ToroughlydeterminethenumberofrequiredNACGatewaysperSecurityDomain,usethe
followingformula:
NumberofauthenticatingendsystemsinaSecurityDomain/Concurrentendsystems
supportedbygatewaytype=the
numberofrequiredgatewaysofthattypeperSecurity
Domain.
Forexample,ifyouhave9000endsystemsconnectingtoaSecurityDomain,andyouwillbe
usingSNSTAGITAappliances,thentheformulawouldbe:
9000/3000=3requiredITAappliances
ForeachswitchinaparticularSecurity
Domain,themaximumnumberofauthenticatingend
systemsthatmaybeconnectedtotheswitchatanyonemomentmustbeconsideredwhen
associatingaswitchtoaparticularNACGatewayappliance.Multipleintelligentswitches
residinginsameSecurityDomainmaybepointedtothesameNACGateway,providedthe
maximumnumberofauthenticatingendsystemsfortheparticularNACGatewayisnot
exceeded.(NotethattwoswitchesindifferentSecurityDomainscannotbeassociatedtothe
sameNACGateway.)
ConfigurationofNACGatewayredundancyforeachswitchinaSecurityDomain.
NACGatewayredundancyforaparticularswitchisachievedby
configuringtwodifferent
NACGatewaysasprimaryandsecondaryRADIUSserversforthatswitch,asdepictedin
Figure 55onpage 521.WhenconnectivitytotheprimaryNACGatewayislost,the
secondaryNACGatewayisused.Notethatthisconfigurationsupportsredundancyandnot
loadsharing,andthesecond
NACGatewaywillonlybeusedintheeventthattheprimary
NACGatewaybecomesunreachable.
Table 5-4 End-System Limits for NAC Gateways
NAC Gateway Model Concurrent End-Systems Supported
NSTAG-FE100-TX Up to 500
7S-NSTAG-01(-NPS) Up to 1000
NSTAG-GE250-TX Up to 1250
SNS-TAG-LPA Up to 2000
SNS-TAG-HPA Up to 3000
SNS-TAG-ITA Up to 3000