General Management Considerations
Enterasys NAC Controller Hardware Installation Guide 6-3

General Management Considerations

ThefollowingaregeneralNAC Controllermanagementconfigurationconsiderations:
•TheLayer3NACControllerispositionedinbetweentworoutersonthenetwork.Onlyone
VLAN/subnetspansbetweentheseroutersasshowninFigure 62.ForLayer3NAC
Controllerconfiguration,alldatatraffic(nonmanagementtraffic)traversingtheNAC
Controllerbetweentheupstreamrouterandthedownstreamroutermustbeuntagged.The
reasonforthisisthattheNACControllerdoesnotpreserveVLANtaggingfordatatraffic
traversingtheappliance,regardlessofwhetherinbandoroutofbandmanagementis
configured.Theupstreamanddownstreamroutersmustbeconfiguredwithroutedinterfaces
forthisVLAN/subnetasshownbelowwithIPaddresses20.20.20.2/24and202020.1/24.
Figure 6-2 Layer 3 NAC Controller Positioning
•WhenusingInBandmanagement:
–TwoIPaddressesareassignedtotheNACControllerwhenconfiguredforinband
management;amanagementIPaddressfortheNACControllerEngineanda
managementIPaddressfortheNACControllerPEP.
–TheNACControllerEngineIPaddressandNACControllerPEPIPaddresses,masks,and
gatewaymustbepartofthesamesubnetthatspanstheupstreamanddownstream
routers.
–NomanagementVLANIDisrequired.AllmanagementtrafficsourcedfromtheNAC
ControllerEngineandNACControllerPEPegressestheupstreamanddownstreamports
oftheNACControlleruntaggedontotheVLANthatspansthetworouters,showas
shownbelow.
–AremediationwebserverIPaddressisnotrequired.Theremediationwebserverisrun
offofthemanagementIPaddressoftheNACControllerEngine.
–AlldirectlyconnectedmanagementandrouterIPaddressesonthissubnetmustbe
specifiedduringthesetupprocessinordertoestablishIPconnectivityintothetopology.
SeeFigure 65onpage 65foradiagramonlayer3InBandmanagement.SeeFigure 63on
page 64foradiagramonlayer2InBandmanagement.
•WhenusingOutOfBandmanagement:
–ThreeIPaddressesareassignedtotheLayer3NACControllerwhenconfiguredfor
outofbandmanagement;amanagementIPaddressandremediationIPaddressforthe
NACControllerEngineandamanagementIPaddressfortheNACControllerPEP.