Specifications
Inline NAC Design Procedures
5-30 Design Procedures
2. Determine the Number of NAC Controllers
ThenumberofNACControllerstobedeployedonthenetworkisafunctionofthefollowing
parameters:
•Thenetworktopology.
BecausetheNACControllerisplacedinlinewithtrafficsourcedfromconnectingend‐
systems,thenumberofNACControllersrequiredisdirectlydependentonthenetwork
topology.Afterthelocationof
theNACControllerisidentifiedfromthenetworktopology,the
minimumnumberofNACControllerscanbedetermined.
•ThenumberofSecurityDomainsconfiguredonthenetwork.
EachNACControllercanbeassociatedtoonlyoneSecurityDomain.Therefore,thenumber
ofNACControllersdeployedonthenetworkwillbegreater
thanorequaltothenumberof
SecurityDomainsconfiguredinNACManager.TosupportredundancyperSecurityDomain,
atleasttwoNACControllersmustbedeployedperSecurityDomain,asdiscussedbelow.
•ThenumberofusersanddevicesthatareconnectedtoeachSecurityDomain.
EachNACControllerappliancehasthe
capabilityofsupportingupto2000end‐systems
connecteddownstreamasshowninthefollowingtable.
ToidentifytheminimumnumberofNACControllersrequiredtosupportinlineNAC,usethe
followingformula:
Numberofconnectingend‐systemsinaSecurityDomain/Concurrentend‐systems
supportedbycontrollertype=
thenumberofrequiredNACControllersofthattype,per
SecurityDomain.
•TheconfigurationofNACControllerredundancy.
ToachieveredundancyateachlocationinthenetworkwheretheNACControlleris
positioned,anadditionalNACControllerisrequired,essentiallydoublingthetotalnumberof
requiredNACControllers.Redundancyimplementationdiffers
betweenLayer2andLayer3
Controllers.
ForaLayer2NACController,redundancyisachievedintwodifferentways.Redundancyfor
theNACPolicyEnforcementPoint(PEP)componentoftheNACControllerisachievedby
implementing802.1w/sspanningtreebetweentheredundantNACControllersasshownin
Figure 5‐9on
page 5‐31.RedundantLayer2NACControllersareactive‐passivewhenonly
onespanningtreeforoneVLANisconfiguredbetweentheNACControllers,andareactive‐
activewhenmultiplespanningtreesformultipleVLANsareconfiguredbetweenthe
redundantNACControllers.IfNACController#1ʹsPolicyEnforcementPoint(PEP)
stops
forwardingtraffic,thenetworkwillautomaticallyconvergevia802.1w/sspanningtreeto
forwardtrafficthroughNACController#2.
RedundancyfortheNACEnginecomponentoftheNACControllerisachievedbythe
redundantNACControllersusingeachotherasbackupRADIUSservers.IfNACController
#1ʹsEnginestops
processingRADIUSauthenticationrequests,theredundantNACEngine
willtakeoverprocessingRADIUSmessagesasshowninFigure 5‐9onpage 5‐31.
Table 5-5 End-System Limits for NAC Controllers
NAC Controller Model Concurrent End-Systems Supported
7S4280-19-SYS Up to 2000
2S4082-25-SYS Up to 2000