Inline NAC Design Procedures
Enterasys NAC Design Guide 5-31
Figure 5-9 Layer 2 NAC Controller Redundancy
ForaLayer3NACController,redundancyisachievedbyimplementingredundantLayer3
NACControllersonadjacent,butseparatenetworksasshowninFigure 5‐10.TheNAC
Controllersmustbeindifferentnetworks,andadynamicroutingprotocolsuchasOSPFor
RIPmustbeconfiguredbetweenthe
upstreamanddownstreamroutersthatarepositionedon
eithersideoftheNACControllers.RedundantLayer3NACControllersareactive‐active,in
thattrafficfromadownstreamroutermaypassthrougheitheroftheredundantLayer3NAC
Controllerswithequalcostmultipathforwardingimplementedfortheconfigureddynamic
routing
protocol.IfNACController#1(PEPorNACEngine)stopsforwardingtraffic,the
networkwillautomaticallyconvergeusingtheconfiguredroutingprotocoltoforwardtraffic
throughNACController#2.NotethattheNACControllersdonotroutepacketsanddonot
participateinthelayer3topology.
Figure 5-10 Layer 3 NAC Controller Redundancy