Designing Access Controls

 

 

 

Choose RADIUS Servers

Table 3-71. General Combination for the NAC 800

 

 

 

 

 

 

PEPs

PDPs

Policy Repository

Credential

 

 

 

 

Repository

 

• Switch

NAC 800

IDM agent

Directory service

 

AP

Wireless Edge Services Module

Integrated server/proxy—At least some RADIUS servers are built into the PEPs. The built-in RADIUS servers proxy requests to one or more NAC 800s, which check credentials against a directory service and receive policies from their IDM agent.

Table 3-72. Integrated Server/Proxy for the NAC 800

PEPs with built-in

Proxy PDPs

Policy Repository

Credential

PDPs

 

 

Repository

 

 

 

 

• AP 530

NAC 800

IDM agent

Directory service

Wireless Edge Services Module

Turnkey server—PEPs send authentication requests to one or more turnkey NAC 800s, which are managed by IDM and store all creden- tials and policies.

Table 3-73. Turnkey Server Combination for the NAC 800

PEPs

PDP with Policy/Credential Repository

Switch

NAC 800 managed by IDM and using its local

AP

database

Wireless Edge Services Module

Integrated server/proxy to turnkey server—At least some RADIUS servers are built in the PEPs. The built-in RADIUS servers proxy requests to one or more NAC 800s, which are managed by IDM and store all credentials and policies.

3-95