Installation guide
Deployment Flexibility
Sentriant AG Software Installation Guide, Version 5.2
8
The following figure shows an example installation scenario for a setup with enforcement with static
routes on the endpoint.
Deploying Sentriant AG Using 802.1X
To configure Sentriant AG as 802.1X-enabled, install it with one of three different configurations,
depending on your network environment (see Figure 8):
1 Use the built-in Sentriant AG RADIUS server to proxy to any other RADIUS server. In this
configuration, the switch performs the 802.1X authentication against the Sentriant AG RADIUS
server, which proxies the request to another RADIUS server. During the return proxy of the
authentication request, the Sentriant AG ES instructs the switch in which VLAN is to place the
endpoint based on its test status.
2 Use the built-in Sentriant AG RADIUS server and user accounts. In this configuration, the switch
performs the 802.1X authentication against the Sentriant AG RADIUS server. The Sentriant AG ES
instructs the switch in which VLAN to place the endpoint, based on its test status.
3 Use the IAS plug-in to integrate with your existing radius server. In this configuration, the switch
performs the 802.1X authentication against the Microsoft Internet Authentication Service (IAS)
RADIUS server. A Sentriant AG plug-in to the IAS RADIUS server is available that instructs the
switch in which VLAN to place the endpoint based on its test status.
Figure 7: Single-server Installation, Endpoint Static Route Enforcement