The NAC Controller Policy Configuration
Enterasys NAC Controller Hardware Installation Guide 6-21
Modifying the Downstream Default Policy
Dependingonthenetworkconfigurationorcircumstances,itʹspossiblethattrafficfromthe
upstreamsidecouldbereroutedtotheNACController,whereitwouldbeauthenticatedusing
theupstreamsourceIPaddress.Toavoidthisproblem,addaLayer3IPAddressSourceruleto
thedownstreamdefaultpolicyconfiguredontheNACController,usingtheupstreamIPsubnets
(orcriticalserverslocatedintheupstream)andcontainingthetraffictoaVLAN.