Enterasys 2S4082-25-SYS Installationsanleitung Seite 84

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 108
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 83
The NAC Controller Policy Configuration
6-16 Initializing the NAC Controller
The NAC Controller Policy Configuration
ReviewthefollowingconsiderationspriortoconfiguringpolicyonNACControllerPEPdevices:
Setup the VLAN Configurations
NACControllerPEPVLANconfig urationmustconformwiththe requirementsofyournetwork
topology.DuringNACControllerEnginemanagementinitializationforOutOfBand
managementconfigurations,youenteredamanagementVLANforthisNACController.For
OutOfBandconfigurations,thismanagementVLANenteredduringinitializationispushed
downtothe
PEP.
ForInBandmanagement,theNACControllermanagementVLANsareconfigured.The
managementVLANSareVLAN1forL2andVLAN90forL3.TherearealsoanumberofVLANs
configuredsuchas3056forPortMirroringor3089forQuarantine.Itisimportantthatyounote
these
defaultsanddetermineiftheyaredesirableorinconflictwithVLANsalreadypresentin
yournetwork.
TodisplaycurrentVLANsettingsandmakeanychangestoVLANconfigurationsprovidea
consoleconnectiontotheNACControllerPEPhost.0.1.
ForL2accesstotheCLIforNACControllerPEPconfiguration,connect
theconsoletotheNAC
ControllerPEPCOMport.TheCOMportlocationisshowninFigure 623.TheNACController
PEPCLIpromptwilldisplay.
Figure 6-23 NAC Controller PEP COM Port Location
Usetheshowportvlanhost.0.1commandtodisplaythecurrentVLANconfiguratinforthisNAC
ControllerPEP.Usetheshowvlancommand
todisplayallconfiguredVLANs.Onceyouhave
determinedchangesthatmayberequired,referencetheDFEPlatinumandDiamondSeries
ConfigurationGuideforinformationpertainingtoVLANconfiguration.
NAC Controllers Require Separate Domains
TheNACControllercanbeconfiguredinoneoftwomodesofoperation:L2orL3.Themodeof
operationcontrolshowconnectingendsystemsaredetectedbytheNACControlleronthe
networkandisselectedbasedonwheretheNACControllerispositionedinthenetworkin
relationto
theseendsystems.IftheNACControllerispositionedbeforethefirstroutedboundary
forconnectingendsystemsclosertotheaccessedgeofthenetwork,theL2NACControllermode
isutilized.IftheNACControllerispositionedafterthefirstroutedboundarydeeperinsidethe
network,theL3
NACControllermodeisutilized.
Seitenansicht 83
1 2 ... 79 80 81 82 83 84 85 86 87 88 89 ... 107 108

Kommentare zu diesen Handbüchern

Keine Kommentare