Addendum to the ProCurve Access Control Security Design Guide

ProCurve Access Control Solution 2.1

provides a third option: You can install RDAC on the Windows DHCP server, and as long as the server can relay DHCP information to the NAC 800, you can place it anywhere on the network.

RDAC is also used for the new DHCP plug-in deployment.

DHCP Plug-in Deployment

Previously, the NAC 800 supported a DHCP inline deployment. In a DHCP inline deployment, the NAC 800 is placed between the DHCP server and the rest of the network. If you have multiple DHCP servers, you can attach the servers to a switch and place the NAC 800 between the switch and the rest of the network. (See Figure A-1.)

Figure A-1. DHCP Inline Deployment—Single NAC 800 and Multiple DHCP Servers That Are Attached to the Same Switch

If you are using Windows 2003 DHCP Servers, you can use the DHCP plug-in deployment method. (See Figure A-2.) The DHCP plug-in deployment does not require the NAC 800 to be placed between the network and the DHCP servers. Instead, the DHCP servers can be located on any subnetwork on the network, as long as they can communicate with the NAC 800. (In other words, your network must be set up to route traffic between the DHCP servers and the NAC 800.)

A-8

Page 312
Image 312
HP Access Control Client Software manual Dhcp Plug-in Deployment