Specifications

Inline NAC Design Procedures
5-30 Design Procedures
2. Determine the Number of NAC Controllers
ThenumberofNACControllerstobedeployedonthenetworkisafunctionofthefollowing
parameters:
•Thenetworktopology.
BecausetheNACControllerisplacedinlinewithtrafficsourcedfromconnectingend
systems,thenumberofNACControllersrequiredisdirectlydependentonthenetwork
topology.Afterthelocationof
theNACControllerisidentifiedfromthenetworktopology,the
minimumnumberofNACControllerscanbedetermined.
•ThenumberofSecurityDomainsconfiguredonthenetwork.
EachNACControllercanbeassociatedtoonlyoneSecurityDomain.Therefore,thenumber
ofNACControllersdeployedonthenetworkwillbegreater
thanorequaltothenumberof
SecurityDomainsconfiguredinNACManager.TosupportredundancyperSecurityDomain,
atleasttwoNACControllersmustbedeployedperSecurityDomain,asdiscussedbelow.
•ThenumberofusersanddevicesthatareconnectedtoeachSecurityDomain.
EachNACControllerappliancehasthe
capabilityofsupportingupto2000endsystems
connecteddownstreamasshowninthefollowingtable.
ToidentifytheminimumnumberofNACControllersrequiredtosupportinlineNAC,usethe
followingformula:
NumberofconnectingendsystemsinaSecurityDomain/Concurrentendsystems
supportedbycontrollertype=
thenumberofrequiredNACControllersofthattype,per
SecurityDomain.
•TheconfigurationofNACControllerredundancy.
ToachieveredundancyateachlocationinthenetworkwheretheNACControlleris
positioned,anadditionalNACControllerisrequired,essentiallydoublingthetotalnumberof
requiredNACControllers.Redundancyimplementationdiffers
betweenLayer2andLayer3
Controllers.
ForaLayer2NACController,redundancyisachievedintwodifferentways.Redundancyfor
theNACPolicyEnforcementPoint(PEP)componentoftheNACControllerisachievedby
implementing802.1w/sspanningtreebetweentheredundantNACControllersasshownin
Figure 59on
page 531.RedundantLayer2NACControllersareactivepassivewhenonly
onespanningtreeforoneVLANisconfiguredbetweentheNACControllers,andareactive
activewhenmultiplespanningtreesformultipleVLANsareconfiguredbetweenthe
redundantNACControllers.IfNACController#1ʹsPolicyEnforcementPoint(PEP)
stops
forwardingtraffic,thenetworkwillautomaticallyconvergevia802.1w/sspanningtreeto
forwardtrafficthroughNACController#2.
RedundancyfortheNACEnginecomponentoftheNACControllerisachievedbythe
redundantNACControllersusingeachotherasbackupRADIUSservers.IfNACController
#1ʹsEnginestops
processingRADIUSauthenticationrequests,theredundantNACEngine
willtakeoverprocessingRADIUSmessagesasshowninFigure 59onpage 531.
Table 5-5 End-System Limits for NAC Controllers
NAC Controller Model Concurrent End-Systems Supported
7S4280-19-SYS Up to 2000
2S4082-25-SYS Up to 2000