Inline NAC Design Procedures
Enterasys NAC Design Guide 5-29
However,theclosertheNACControllerisplacedtotheedgeofthenetwork,themoreNAC
Controllersarerequiredonthenetwork,increasingNACdeploymentcostandcomplexity.
Conversely,whenmovingtheNACControllertowardsthecoreofthenetwork,fewerNAC
Controllersarerequired,decreasingNACdeploymentcostand
complexity,butalsodecreasing
thelevelofsecurity.
ForimplementingNAConwiredandwirelessLANs,itisrecommendedthattheLayer2NAC
Controllerispositionedbetweentheaccesslay eranddistributionlayerbeforethefirstroutedhop
inthenetwork.Asanalternative,theNACControllermaybepositioned
deeperintothenetwork
afterthefirstroutedhopusingtheLayer3configuration.TheLayer3NACControllercanalsobe
positionedafteraVPNconcentratororWANconnectiontoimplementNACforremoteusers.
Unliketheout‐of‐bandNACdesign,theimplementationofremediationand/orMAC(network)
registrationdoesnotaffectthelocationoftheNACController.TheNACControllerwill
appropriatelyinterceptwebtrafficforthepurposeofremediationandregistration.
Lastly,itshouldbeunderstoodthatsomeadvantagesexistwiththedeploymentofaLayer2NAC
ControlleroveraLayer3NACController,whichmay
affectthedecisionofhowNACControllers
arepositioned.WhileaLayer2NACControlleralwaysknowstheMACaddressofthe
downstreamconnectedend‐system,theLayer3NACControllermaynotbeabletodeterminethe
MACaddressofadownstreamend‐system(denotedas“Unknown”inNACManager.)
TechniquessuchasNetBIOSlookupsandDHCPsnoopingareimplementedtoattempttoresolve
theIPaddressofthedownstreamconnectedend‐systems;however,scenariosexistwheretheIP
addressofthedownstreamend‐systemmaynotbedetermined.
TheMACaddressofadownstreamend‐systemwillbedetermined
bytheNACControllerinthe
followingscenarios:
•End‐systemssupportNetBIOSandahostfirewalldoesnotdropinboundNetBIOSrequests
fortheLANconnection.
•DHCPisimplementedandtheDHCPserverexistsupstreamfromtheNACController.
SincetheLayer3NACControllermaynotbeabletodeterminethe
MACaddressofa
downstreamend‐system,“LockMAC”andMACoverridesarenotapplicabletoLayer3NAC
Controllers.Furthermore,MAC(network)registrationmaynotbeimplementedwhentheMAC
addressofadownstreamconnectedend‐systemisunknown.Inthiscase,theend‐systemis
assignedtheSecurityDomain’s
defaultNACconfiguration.