Enterasys Networks 9034385 Plumbing Product User Manual


 
Out-of-Band NAC Design Procedures
Enterasys NAC Design Guide 5-21
Figure 5-5 NAC Gateway Redundancy
ItisimportantthatthesecondaryNACGatewaydoesnotexceedmaximumcapacityifthe
primaryNACGatewayfailsonthenetwork.Forexample,let’ssaythattwoNACGateways,
bothrunningatmaximumloadonthenetwork,arebeingusedbysixswitches.NACGateway
#1istheprimary
gatewayforswitchA,switchB,andswitchC,andNACGateway#2isthe
primarygatewayforswitchD,switchE,andswitchF.Inthisscenario,NACGateway#1
shouldnotbeconfiguredtoserveassecondaryforNACGateway#2andviceversa.Thisis
becauseifNAC
Gateway#1fails,NACGateway#2,whichisalreadyrunningatmaximum
capacitybeforeNACGateway#1ʹsfailure,willnotbeabletohandletheendsystemsfailing
overfromNACGateway#1.Toavoidexceedingtheselimits,extraNACGatewayappliances
mustbedeployedonthenetworkto
serveassecondaryNACGatewaysforthesesixswitches.
Tosummarize,NACGatewayredundancymaybeaccomplishedusingtwodifferentapproaches:
•Activestandbyredundancy
Inthisredundancyapproach,asetofswitchesareconfiguredtousethesameprimaryNAC
Gateway(assumingtheseswitchesobservetheNACGatewayʹscapacitylimitations
previously
described)andusethesamesecondaryNACGatewayasabackup(assumingthe
secondaryNACGatewayisthesamemodelastheprimary).ThesecondaryNACGatewayis
notconfiguredasaprimaryNACGatewayforanyswitchonthenetworkandthereforeis
inactiveuntilaprimaryNACGateway
fails.Forexample,ifswitchA,switchB,andswitchC
useNACGateway#1asaprimarygateway,thenallthreeswitchescanbeconfiguredtouse
NACGateway#2onthenetworkasthebackup.Inthisconfiguration,ifswitchA,switchB,or
switchClosesconnectivityto
NACGateway#1,theswitchwouldseamlesslytransitionto
usingNACGateway#2.Intheworstcasescenariowhereallthreeswitchesloseconnectivity
toNACGateway#1,NACGateway#2wouldbeabletohandleallauthenticationrequests
fromthesethreeswitches.Inthisredundancyconfiguration,NACGateway#2
iscompletely
idleonthenetworkandonlyutilizedifoneoftheswitchescannotcommunicatetoNAC
Gateway#1.
•Activeactiveredundancy
Inthisredundancyapproach,theprim aryNACGatewayforoneswitchisasecondaryNAC
Gatewayforanotherswitch.Forthisconfiguration,thesameprimaryNACGatewayis
utilized
foragroupofswitches,withthisNACGatewayrunningatonlyhalfthemaximum
load.AnothergroupofswitchesutilizesadifferentprimaryNACGateway(assumingitisthe
samemodel)alsorunninghalfthemaximumload.Then,eachgroupofswitchescanusethe
otherNACGatewayas
thesecondarygateway.Thisredundancyconfigurationguarantees
thatintheworstcasescenario,whenallswitchesinonegrouplosecommunicationtotheir