Specifications
Identify Inline or Out-of-band NAC Deployment
Enterasys NAC Design Guide 4-11
Remote Access VPN
Inmanyenterpriseenvironments,aVPNconcentratorlocatedatthemainsiteconnectstothe
InternettoprovideVPNaccesstoremoteusers.Inthisscenario,thereisnoconceptofintelligent
andnon‐intelligentedgeswitchesbecausetheentrypointtothemainsiteistheVPNconcentrator.
Inthis
scenario,theNACControllermustbeusedtoimplementNACforremoteaccessVPNend‐
systems,anditshouldbepositionedbehindtheVPNconcentratorthatprovidesremoteaccess
VPN.Again,reverseproxyVPNormany‐to‐oneNATimplementedonadownstreamdevicefrom
theNACControllerisnot
supportedintheEnterasysNACsolution.
Identify Inline or Out-of-band NAC Deployment
BasedontheNACdeploymentmodelyouselected,andtheresultsofyournetworkinfrastructure
evaluation,youmustidentifywhetherout‐of‐bandNACorinlineNACwillbedeployedinthe
differentareasofyournetwork.Withthedecisiontoimplementout‐of‐bandNACwiththeNAC
Gateway,and/or
inlineNACwiththeNACController,thenextdesignstepistodetermineyour
specificenterpriserequirementsfortheselectedNACsolution,andidentifythenumberofNAC
appliances,andtheirlocationandconfigurationonthenetwork.
Summary
ThefirststepwhenplanningyourNACdeployment,istoidentifytheNACdeploymentmodel,
oraphasedimplementationofmultipledeploymentmodels,thatmeetsyourNACbusiness
objectives.Onceyouhaveselectedadeploymentmodel,youcanusethefourfollowingstepsto
evaluateyourcurrentnetworkinfrastructureanddetermine
yourNACcomponentrequirements.
1. Identifythe“intelligentedge”inyournetwork,ifitexists.Thisinformationwillbeusedto
helpyouselectwhichNACappliance,theNACGatewayorNACController,bestsuitsyour
networkinfrastructure.
AnintelligentedgeisrequiredwhentheNACGatewayisutilizedforimplementingout‐
of‐
bandNAC.TheNACGatewayapplianceleveragestheintelligentedgeofthenetworkto
implementtheauthenticationandauthorizationofconnectingend‐systems.
Innetworkswithnon‐intelligentdevicesattheaccessedge,itisnotnecessarytoreplacethese
non‐intelligentdevicestobeabletoimplementout‐of
‐bandNACwiththeNACGateway.
Instead,theEnterasysMatrixN‐seriesswitchcanbepositionedupstreamfromnon‐intelligent
devices(suchasinthedistributionlayer)toimplementtheauthenticationandauthorization
functionsfordownstreamconnecteddevices.
Ifthenetworkdoesnothaveanintelligentedge,thentheNACController
mustbedeployed
inordertoprovidetheauthenticationandauthorizationcapabilitiesrequiredfor
implementingnetworkaccesscontrol.
2. Evaluatethenetworkauthenticationmethodcurrentlybeingused,andhowthedeployment
ofEnterasysNACwillaffectit.(Thisstepisnotrequiredifyouhavedeterminedthatthe
networkdoesnothave
anintelligentedgeandtheinlineNACControllerwillbe deployed.)
Ifauthenticationisnotconfiguredonthenetwork,out‐of‐bandNACcanbedeployedwith
minimalconfigurationbyimplementingMACauthenticationontheintelligentedgeofthe
network(iftheedgeswitchessupportMACauthentication).
Ifauthenticationiscurrently
deployedonthenetworkwith802.1X,web‐based,and/orMAC
authentication,out‐of‐bandNACisconfiguredtoproxyRADIUSauthenticationrequests
receivedfromtheswitchesattheintelligentedgeofthenetworktothebackendRADIUS