Enterasys Networks 9034385 Plumbing Product User Manual


 
Out-of-Band NAC Design Procedures
5-22 Design Procedures
primaryNACGateway,thetransitiontothesecondaryNACGatewaywillnotexceed
maximumcapacity.
TosupportredundancywithinaSecurityDomainforeitherapproach,oneadditionalNAC
Gateway(ofthesamemodelorwithincreasedcapacity)mustbedeployedperSecurityDomainin
additiontotheNACGatewaysdeployedto
handlethemaximumnumberofconcurrentend
systemsconnectingtothenetwork.
ItisimportanttonotethateachNACGatewaycanbeconfiguredtoproxyRADIUSauthentication
requeststoaparticularRADIUSserver.Therefore,iftwoswitchesinthenetworkprovideaccess
to802.1Xorwebbasedauthenticatingusers,and
thecredentialsfortheusersconnectedtoeach
switcharelocatedondifferentRADIUSserversdeployedonthenetwork,theneachswitchmust
beconfiguredtouseitsownNACGateway.EachNACGatewayisthenconfiguredtouseits
respectiveRADIUSserver.Forexample,anenterprisenetworkthatutilizes
aparticularRADIUS
serverforthe802.1Xauthenticationofwirelessusers,woulduseadifferentRADIUSserverfor
authenticatingwiredusers.Inthiscase,thesameNACGatewaycouldnotbeusedfortheswitch
providingwirelessaccessandtheswitchprovidingwiredaccess.
3. Determine NAC Gateway Location
AfterdeterminingthenumberofNACGatewaysrequiredfortheNACdeployment,thenextstep
istodetermineNACGatewaylocationonthenetwork.ThisisdependentontheNAC
deploymentmodelthatisimplementedonthenetwork.
IftheNACdeploymentdoesnotimplementremediationofquarantinedendsystemsor
MAC
(network)registrationofnewdevicesonthenetwork,thentheNACGatewaysarelocatedinthe
authenticationpathofconnectingendsystemsasaproxyRADIUSserver.Thismeansthatthe
RADIUSclientontheaccesslayerswitchescommunicatesdirectlytotheNACGatewayover
UDP/IP,andtheNACGateway
inturncommunicatestoabackendRADIUSserver.Therefore,the
onlyrequirementforNACGatewayplacementisthataroutableIPforwardingpathexists
betweeneachNACGatewayanditsassociatedaccesslayerswitches.
OneoptionistoplaceallNACGatewaysinthedatacenter,possiblyadjacenttotheRADIUS
serversdeployedonthenetwork.Becausetheendsystemassessmentisnotdirectlyexecuted
fromtheNACGateways,thechoiceofthelocationfortheNACGatewaydoesnotimpactthe
NACoperation,assumingIPconnectivitybetweentheaccesslayerswitchesandtheNAC
Gatewaysismaintained.
Forabranch
officedeploymentofNAC,aNACGatewaymaybeinstalledatthebranchofficeor
atthemainsite.TheadvantageoftheNACGatewaybeinginstalledatthebranchofficeisthat
authenticationtrafficgeneratedfromendsystemsatthebranchofficewillnotutilizethe
bandwidthoftheWAN
connection,unlessauthenticationrequestsareproxiedtoaRADIUS
serverdeployedatthemainsite.IftheNACGatewayisinstalledatthebranchofficelocation,
NACManagerrequirescommunicationtotheNACGatewayonlyduringconfiguration,
minimizingthebandwidthconsumptionovertheWANlink.TheNACGatewayneednot
communicatewithNACManagerfortheauthentication,assessment,andauthorizationof
connectingendsystems.
IfeitherremediationorMACregistrationisimplemented,theNACGatewaysthatareperforming
remediationandregistrationserverfunctionalityviawebredirection,mustbestrategically
positionedonthenetworkforendusernotification.TheNACGatewaymust
beinstalledona
networksegmentdirectlyconnectedtotherouterorroutersthatexistintheforwardingpathfor
HTTPtrafficfromendsystemsthatmaybequarantinedorunregistered.Thisisbecausepolicy
basedroutingwillbeconfiguredontherouterorrouterstoredirectthewebtrafficsourced
from
quarantinedandunregisteredendsystemstotheNACGatewaytoservetheremediationand
registrationwebpage.