Specifications

Identify Inline or Out-of-band NAC Deployment
Enterasys NAC Design Guide 4-11
Remote Access VPN
Inmanyenterpriseenvironments,aVPNconcentratorlocatedatthemainsiteconnectstothe
InternettoprovideVPNaccesstoremoteusers.Inthisscenario,thereisnoconceptofintelligent
andnonintelligentedgeswitchesbecausetheentrypointtothemainsiteistheVPNconcentrator.
Inthis
scenario,theNACControllermustbeusedtoimplementNACforremoteaccessVPNend
systems,anditshouldbepositionedbehindtheVPNconcentratorthatprovidesremoteaccess
VPN.Again,reverseproxyVPNormanytooneNATimplementedonadownstreamdevicefrom
theNACControllerisnot
supportedintheEnterasysNACsolution.
Identify Inline or Out-of-band NAC Deployment
BasedontheNACdeploymentmodelyouselected,andtheresultsofyournetworkinfrastructure
evaluation,youmustidentifywhetheroutofbandNACorinlineNACwillbedeployedinthe
differentareasofyournetwork.WiththedecisiontoimplementoutofbandNACwiththeNAC
Gateway,and/or
inlineNACwiththeNACController,thenextdesignstepistodetermineyour
specificenterpriserequirementsfortheselectedNACsolution,andidentifythenumberofNAC
appliances,andtheirlocationandconfigurationonthenetwork.
Summary
ThefirststepwhenplanningyourNACdeployment,istoidentifytheNACdeploymentmodel,
oraphasedimplementationofmultipledeploymentmodels,thatmeetsyourNACbusiness
objectives.Onceyouhaveselectedadeploymentmodel,youcanusethefourfollowingstepsto
evaluateyourcurrentnetworkinfrastructureanddetermine
yourNACcomponentrequirements.
1. Identifythe“intelligentedge”inyournetwork,ifitexists.Thisinformationwillbeusedto
helpyouselectwhichNACappliance,theNACGatewayorNACController,bestsuitsyour
networkinfrastructure.
AnintelligentedgeisrequiredwhentheNACGatewayisutilizedforimplementingout
of
bandNAC.TheNACGatewayapplianceleveragestheintelligentedgeofthenetworkto
implementtheauthenticationandauthorizationofconnectingendsystems.
Innetworkswithnonintelligentdevicesattheaccessedge,itisnotnecessarytoreplacethese
nonintelligentdevicestobeabletoimplementoutof
bandNACwiththeNACGateway.
Instead,theEnterasysMatrixNseriesswitchcanbepositionedupstreamfromnonintelligent
devices(suchasinthedistributionlayer)toimplementtheauthenticationandauthorization
functionsfordownstreamconnecteddevices.
Ifthenetworkdoesnothaveanintelligentedge,thentheNACController
mustbedeployed
inordertoprovidetheauthenticationandauthorizationcapabilitiesrequiredfor
implementingnetworkaccesscontrol.
2. Evaluatethenetworkauthenticationmethodcurrentlybeingused,andhowthedeployment
ofEnterasysNACwillaffectit.(Thisstepisnotrequiredifyouhavedeterminedthatthe
networkdoesnothave
anintelligentedgeandtheinlineNACControllerwillbe deployed.)
Ifauthenticationisnotconfiguredonthenetwork,outofbandNACcanbedeployedwith
minimalconfigurationbyimplementingMACauthenticationontheintelligentedgeofthe
network(iftheedgeswitchessupportMACauthentication).
Ifauthenticationiscurrently
deployedonthenetworkwith802.1X,webbased,and/orMAC
authentication,outofbandNACisconfiguredtoproxyRADIUSauthenticationrequests
receivedfromtheswitchesattheintelligentedgeofthenetworktothebackendRADIUS