Enterasys NAC Controller Hardware Installation Guide 6-1
6

Initializing the NAC Controller

ThischapterprovidesadetaileddiscussionoftheNAC Controllersoftwareinitialzation.

Overview

TheNACControlleriscomposedoftwosubcompents,thePolicyEnforcementPoint(PEP)and
theEngine.EachcomponenthasanIPaddress,andthecomponentsaremanagedjointlyinthe
operationoftheNACControlleronthenetwork.WhenconfiguringtheNACControllerforIP
connectivityinthenetworktopology,itisimportanttoconsiderboththeNACControllerPEPand
NACControllerEngineasdescribedbelow.
TwomanagementconfigurationsfortheNACControlleraresupporteddependingonthe
managementtopologyofyournetwork:inbandmanagementoroutofbandmanagement.For
theinbandmanagementconfiguration,allmanagementtrafficsourcedfromtheNACController
isgeneratedontothedataVLANalongwithendsystemtrafficthatistraversingtheappliance.
Fortheoutofbandmanagementconfiguration,allmanagementtrafficsourcedfromtheNAC
ControllerisgeneratedonadifferentVLANthantheendsystemtraffic.Moredetailsaboutthese
managementconfigurationsasrelatedtorequiredsettingsofadjacentnetworkinfrastructure
devicesareexplainedbelow.Eithertheinbandoroutofbandmanagementconfigurationis
supportedfortheLayer2(L2)andLayer3(L3)NACController.Therefore,oneofthefollowing
configurationsmustbeselectedastheinstallationtypeduringtheintializationoftheNAC
Controller:
•Layer2NAC ControllerwithInBandManagement
•Layer2NAC ControllerwithOutOfBandManagement
•Layer3NAC ControllerwithInBandManagement
•Layer3NAC ControllerwithOutOfBandManagement
For information about... Refer to page...
Overview 6-1
General Management Considerations 6-3
Preparation for NAC Controller Initialization 6-6
The NAC Controller Initialization Procedure 6-7
The NAC Controller Policy Configuration 6-16
Note: The NAC Controller software initialization will take place within a single discussion.
Unless otherwise specified, the content of the discussion applies to all four installation
types.