The NAC Controller Policy Configuration
6-16 Initializing the NAC Controller

The NAC Controller Policy Configuration

ReviewthefollowingconsiderationspriortoconfiguringpolicyonNACControllerPEPdevices:

Setup the VLAN Configurations

NACControllerPEPVLANconfigurationmustconformwiththerequirementsofyournetwork
topology.DuringNACControllerEnginemanagementinitializationforOutOfBand
managementconfigurations,youenteredamanagementVLANforthisNACController.For
OutOfBandconfigurations,thismanagementVLANenteredduringinitializationispushed
downtothePEP.
ForInBandmanagement,theNACControllermanagementVLANsareconfigured.The
managementVLANSareVLAN1forL2andVLAN90forL3.TherearealsoanumberofVLANs
configuredsuchas3056forPortMirroringor3089forQuarantine.Itisimportantthatyounote
thesedefaultsanddetermineiftheyaredesirableorinconflictwithVLANsalreadypresentin
yournetwork.
TodisplaycurrentVLANsettingsandmakeanychangestoVLANconfigurationsprovidea
consoleconnectiontotheNACControllerPEPhost.0.1.
ForL2accesstotheCLIforNACControllerPEPconfiguration,connecttheconsoletotheNAC
ControllerPEPCOMport.TheCOMportlocationisshowninFigure 623.TheNACController
PEPCLIpromptwilldisplay.
Figure 6-23 NAC Controller PEP COM Port Location
Usetheshowportvlanhost.0.1commandtodisplaythecurrentVLANconfiguratinforthisNAC
ControllerPEP.UsetheshowvlancommandtodisplayallconfiguredVLANs.Onceyouhave
determinedchangesthatmayberequired,referencetheDFEPlatinumandDiamondSeries
ConfigurationGuideforinformationpertainingtoVLANconfiguration.

NAC Controllers Require Separate Domains

TheNACControllercanbeconfiguredinoneoftwomodesofoperation:L2orL3.Themodeof
operationcontrolshowconnectingendsystemsaredetectedbytheNACControlleronthe
networkandisselectedbasedonwheretheNACControllerispositionedinthenetworkin
relationtotheseendsystems.IftheNACControllerispositionedbeforethefirstroutedboundary
forconnectingendsystemsclosertotheaccessedgeofthenetwork,theL2NACControllermode
isutilized.IftheNACControllerispositionedafterthefirstroutedboundarydeeperinsidethe
network,theL3NACControllermodeisutilized.