User's Guide

Table Of Contents
Virtual Network Services concepts
hwc_vnsintro.fm
NAC integration with HiPath WLAN
9034530-02, March 2010
232 HiPath Wireless Controller, Access Points and Convergence Software V7.11, User Guide
Step 3
The RADIUS server evaluates the access-request and sends an
Access-Accept message back to the NAC.
The NAC receives the access-accept packet. Using its local database, the
NAC determines the correct policy to apply to this client laptop and updates
the access-accept packet with the policy assignment. The updated
Access-Accept message is forwarded to the HiPath Wireless Controller and
Wireless AP.
Step 4
The HiPath Wireless Controller and Wireless AP apply policy against the client
laptop accordingly. The HiPath Wireless Controller assigns a set of filters to the
client laptop’s session and the Wireless AP allows the client laptop access to the
network.
Step 5
The client laptop interacts with a DHCP server to obtain an IP address.
Step 6
Eventually the client laptop uses its Web browser to access a Website.
The HiPath Wireless Controller determines that the target Website is blocked
and that the client laptop still requires authentication.
The HiPath Wireless Controller sends an HTTP redirect to the client laptop’s
browser. The redirect sends the browser to the Web server on the NAC
Gateway.
The NAC displays an appropriate Web page in the client laptop’s browser.
The contents of the page depend on the current policy assignment
(enterprise, remediation, assessing, quarantine, or unregistered) for the MAC
address.
Step 7
When the NAC determines that the client laptop is ready for a different policy
assignment, it sends a ‘disconnect message’ (RFC 3576) to the HiPath
Wireless Controller.
When the HiPath Wireless Controller receives the ‘disconnect message’ sent
by the NAC, the HiPath Wireless Controller terminates the session for the
client laptop.
The HiPath Wireless Controller forwards the command to terminate the client
laptop’s session to the Wireless AP, which disconnects the client laptop.