Specifications
Scenario 3: Non-intelligent Access Edge (Wired and Wireless)
Enterasys NAC Design Guide 3-9
Itisimportanttonotethatifthewirelessedgeofthenetworkisnon‐intelligentandnotcapableof
authenticatingandauthorizingwirelessend‐systems,itispossibletoaugmentthenetwork
topologytoimplementout‐of‐bandNACwiththeNACGateway.Thiscanbeaccomplished
withoutreplacingthe
physicaledgeofthenetwork,byaddinganintelligentedgeswitchthat
possessesspecializedauthenti cationandauthorizationfeat ures.
TheEnterasysMatrixN‐seriesswitchiscapableofauthenticatingandauthorizingnumerousend‐
systemsconnectedonasingleportthroughMulti‐UserAuthentication (MUA),andmaybe
positionedupstreamfromnon‐
intelligentthird‐partywirelessAPstoactastheintelligentedgeon
thenetwork.TheEnterasysMatrixN‐seriesswitchiscapableofauthenticatingandauthorizing
over1000end‐systemsuplinkedtoasingleMatrixN‐seriesportfromanAP,asetofAPs,or
wirelessswitches.Inthisconfiguration,
theMatrixN‐seriesactsastheintelligentedgeswitchon
thenetwork,althoughnotphysicallylocatedontheaccessedge.Byprovisioningaccessto
networkresourcesontheMatrixN‐seriesviaMUA,end‐systemtrafficdestinedtoadjacent
switchesonthenetworkcanbesecurelycontainedatthe
MatrixN‐seriesport.
Scenario 3: Non-intelligent Access Edge (Wired and Wireless)
Inthenon‐intelligentaccessedgeusescenario,theedgeswitchesandaccesspointsthatcompose
thenetworkaccesslayerarenotcapableofauthenticatingandauthorizingtheconnectingend‐
systemsonthenetwork.
Inthisscenario,inlineNACisimplementedbypositioningtheNACControlleratastrategicpoint
in
thenetworktopology,astheauthorizationpointforend‐systemtrafficenforcement.
TheNACControllermaybepositioneddirectlywithintheVLANwhereend‐systemsare
connectedoracrossoneormoreroutedboundaries.WhentheNACControllerispositioned
withintheVLANwhereend‐systemsareconnected,eachdeviceis
uniquelyidentifiedbyits
associatedMACaddress.WhentheNACControllerispositionedacrossaroutedboundary(for
example,behindaWANrouterlocatedinanenterpriseʹscentralsite),eachend‐systemis
identifiedbyitsassociatedIPaddress.
ThefollowingfigureillustrateshowtheNACControllerandtheother
EnterasysNAC
componentsworktogetherinthenon‐intelligentedgetoprovidenetworkaccesscontrol.