Security Solutions

1-55
Access Control Concepts
ProCurve NAC 800
Figure 1-5. The User Authenticates and Is Placed in the Test VLAN
8. Detecting the endpoint that has been placed on the test VLAN, the NAC
800 begins to check its compliance with NAC policies.
The NAC 800 needs to receive mirrored DHCP traffic on its port 2 to detect
the endpoint.
Note In a cluster of ESs, any ES can test the endpoint; they share information
with each other.
9. When the testing is completed, the endpoint has gained a new posture.
The NAC 800 sends a message to the PEP to force the user to
reauthenticate.