Overview
6-2 Initializing the NAC Controller
TheportslocatedinthelowerrowsoftheNACControllerarereferredtoasʺdownstreamports,ʺ
andconnectdownlinktoinfrastructuredevicessuchasaccesslayerswitchesinthenetwork.The
twogigabitEthernetportslocatedatthetopoftheNACControllerarereferredtoasʺupstream
ports,ʺandconnectuplinktoupstreamdevicessuchascorerouters.The10/100Ethernetport
locatedatthetopoftheNACControllersupportsmanagementfunctionalitywithan
OutOfBandmanagementconfiguration,asexplainedbelow.SeeFigure 61forthelocationofthe
differentNAC Controllerporttypes.
ItisimportanttonotethattheNACControllerappliancetransparentlybridgespacketsatlayer2
fromdownstreamportstoupstreamports,downstreamportstootherdownstreamports,
upstreamportstodownstreamports,andupstreamporttootherupstreamports.Therefore,itis
notnecessarytohavea1:1downstreamporttoupstreamportconfigurationontheNAC
Controller.Furthermore,thetrafficenforcementpointontheNACControllerisimplementedas
trafficingressedthedownstreamportsperMACaddressorIPaddressbeforethetrafficisbridged
throughtheNACControllertoanyotherport.Asaresultoftrafficsourcedfromanendsystem
beingappropriatelyfiltered(forexample:forwarded,discarded,containedtoaVLAN,or
prioritized)uponingresstotheNACControllerportbeforeitisbridged,theflowoftrafficfrom
eachdownstreamendsystemissecurelycontrolledtoallotherdevicesconnectedtoother
upstreamanddownstreamportsontheNACController.
Figure 6-1 NAC Controller Ports
Figure 63throughFigure 66displaytheconfigurationtopologiesforthefourNAC Controller
installationtypes.Ineachcase,upstreamportsontheNACControllerconnecttothenetworkcore
inthedirectionofwheretheNetSightmanagementserverconnectstothenetwork,althoughitis
notnecessarytoconnecttheNetSightmanagementserverupstreamfromtheNACController.
DownstreamportsontheNACControllerconnecttothenetworkedgewhereendsystemsare
connecting.
Note: Figure 6-1 displays a 2S4082-25-SYS, but NAC Controller ports are in the same
location on both systems.