Designing Access Controls

Choose RADIUS Servers

2.Are you concerned with minimizing traffic on WAN links? (And is this concern more important than simplifying management? See step 1.)

WAN links can be relatively slow and costly—both reasons to minimize traffic. The more distributed the architecture, the less access control traffic that must travel between sites.

To eliminate all or most access control related traffic, choose multi- site autonomous or possibly (if you have selected the general option) multi-site fully distributed.

Table 3-68. RADIUS Server Locations (Eliminating Inter-Site Traffic)

Access Control

Access Control

RADIUS Server

RADIUS Server

Credential

Credential

Component

Architecture

Devices

Location

Repository

Repository

Combination

 

 

 

 

 

Location

General

Multi-site fully

Software servers

One or more at

Directory service

Each site (all sites

 

distributed

or NAC 800s

each site

 

in the same

 

 

 

 

 

 

domain or tree)

General

Multi-site

Software servers

One or more at

Directory service

Each site (each its

 

autonomous

or NAC 800s

each site

 

own domain or

 

 

 

 

 

 

tree)

Integrated server

Multi-site

AP 530s or

One or more at

Directory service

Each site (each its

 

autonomous

Wireless Edge

each site

 

own domain or

 

 

Services Modules

 

 

tree)

Integrated server/

Multi-site

AP 530s or

One or more at

Directory service

Each site (each its

proxy

autonomous

 

Wireless Edge

each site

 

own domain or

 

 

 

Services

 

 

tree)

 

 

 

Modules

 

 

 

 

 

Software

 

 

 

 

 

 

servers or NAC

 

 

 

 

 

 

800s

 

 

 

Turnkey server

Multi-site

Software servers

One or more at

Software servers

Each site

 

autonomous

or NAC 800s

each site

or NAC 800s

 

Integrated server/

Multi-site

AP 530s or

One or more at

Software servers

Each site

proxy with turnkey

autonomous

 

Wireless Edge

each site

or NAC 800s

 

server

 

 

Services

 

 

 

 

 

 

Modules

 

 

 

 

 

Software

 

 

 

 

 

 

servers or NAC

 

 

 

 

 

 

800s

 

 

 

Fully integrated

Multi-site

AP 530s or

One or more at

AP 530s or

PEPs at each site

 

autonomous

Wireless Edge

each site

Wireless Edge

 

 

 

Services Modules

 

Services Modules

 

 

 

 

 

 

 

 

To reduce access control related traffic but centralize credentials, choose multi-site distributed AAA with centralized policies.

3-87