Enterasys Networks 9034385 Plumbing Product User Manual


 
Inline NAC Design Procedures
Enterasys NAC Design Guide 5-29
However,theclosertheNACControllerisplacedtotheedgeofthenetwork,themoreNAC
Controllersarerequiredonthenetwork,increasingNACdeploymentcostandcomplexity.
Conversely,whenmovingtheNACControllertowardsthecoreofthenetwork,fewerNAC
Controllersarerequired,decreasingNACdeploymentcostand
complexity,butalsodecreasing
thelevelofsecurity.
ForimplementingNAConwiredandwirelessLANs,itisrecommendedthattheLayer2NAC
Controllerispositionedbetweentheaccesslay eranddistributionlayerbeforethefirstroutedhop
inthenetwork.Asanalternative,theNACControllermaybepositioned
deeperintothenetwork
afterthefirstroutedhopusingtheLayer3configuration.TheLayer3NACControllercanalsobe
positionedafteraVPNconcentratororWANconnectiontoimplementNACforremoteusers.
UnliketheoutofbandNACdesign,theimplementationofremediationand/orMAC(network)
registrationdoesnotaffectthelocationoftheNACController.TheNACControllerwill
appropriatelyinterceptwebtrafficforthepurposeofremediationandregistration.
Lastly,itshouldbeunderstoodthatsomeadvantagesexistwiththedeploymentofaLayer2NAC
ControlleroveraLayer3NACController,whichmay
affectthedecisionofhowNACControllers
arepositioned.WhileaLayer2NACControlleralwaysknowstheMACaddressofthe
downstreamconnectedendsystem,theLayer3NACControllermaynotbeabletodeterminethe
MACaddressofadownstreamendsystem(denotedas“Unknown”inNACManager.)
TechniquessuchasNetBIOSlookupsandDHCPsnoopingareimplementedtoattempttoresolve
theIPaddressofthedownstreamconnectedendsystems;however,scenariosexistwheretheIP
addressofthedownstreamendsystemmaynotbedetermined.
TheMACaddressofadownstreamendsystemwillbedetermined
bytheNACControllerinthe
followingscenarios:
•EndsystemssupportNetBIOSandahostfirewalldoesnotdropinboundNetBIOSrequests
fortheLANconnection.
•DHCPisimplementedandtheDHCPserverexistsupstreamfromtheNACController.
SincetheLayer3NACControllermaynotbeabletodeterminethe
MACaddressofa
downstreamendsystem,“LockMAC”andMACoverridesarenotapplicabletoLayer3NAC
Controllers.Furthermore,MAC(network)registrationmaynotbeimplementedwhentheMAC
addressofadownstreamconnectedendsystemisunknown.Inthiscase,theendsystemis
assignedtheSecurityDomain’s
defaultNACconfiguration.