
Designing Access Controls
Choose RADIUS Servers
This option balances reducing traffic with easing management.
Table 3-69. RADIUS Server Locations (Reducing Inter-Site Traffic)
Access Control | Access Control | RADIUS Server | RADIUS Server | Credential | Credential | |
Component | Architecture | Devices | Location | Repository | Repository | |
Combination |
|
|
|
|
| Location |
General | Software servers | One or more at | Directory service | Central site | ||
| distributed AAA | or NAC 800s | each site |
|
| |
| with centralized |
|
|
|
|
|
| policies |
|
|
|
|
|
Integrated server | AP 530s or | One or more at | Directory service | Central site | ||
| distributed AAA | Wireless Edge | each site |
|
| |
| with centralized | Services Modules |
|
|
| |
| policies |
|
|
|
|
|
Integrated server/ | • | AP 530s or | One or more at | Directory service | Central site | |
proxy | distributed AAA |
| Wireless Edge | each site |
|
|
| with centralized |
| Services |
|
|
|
| policies |
| Modules |
|
|
|
|
| • | Software |
|
|
|
|
|
| servers or NAC |
|
|
|
|
|
| 800s |
|
|
|
Turnkey server | Software servers | One or more at | Software servers | Servers at central | ||
| distributed AAA | or NAC 800s | each site | or NAC 800s | site | |
| with centralized |
|
|
|
|
|
| policies |
|
|
|
|
|
Integrated server/ | • | AP 530s or | One or more at | Software servers | Servers at central | |
proxy with turnkey | distributed AAA |
| Wireless Edge | each site | or NAC 800s | site |
server | with centralized |
| Services |
|
|
|
| policies |
| Modules |
|
|
|
|
| • | Software |
|
|
|
|
|
| servers or NAC |
|
|
|
|
|
| 800s |
|
|
|
|
|
|
|
|
|
|
Example. Choosing your access control architecture is not as daunting as it may
PCU network administrators begin by considering: should the same policies apply at each site? Because the