1-55
Overview of the ProCurve NAC 800
Deployment Methods
On the infrastructure devices that act as default gateways, set up multinetting
on the production VLANs. For example, a routing switch might have this
existing configuration:
■
VLAN 2—IP address = 192.168.8.1/24
■
VLAN 3—IP address = 192.168.12.1/24
You should now add the IP addresses you specified for quarantine subnets’
default gateways:
VLAN 2
IP address = 192.168.8.1/24
IP address = 192.168.9.1/24
VLAN 3
IP address = 192.168.12.1/24
IP address = 192.168.13.1/24
VLAN tagging should already be in place to support the endpoint whether it
is in the quarantine or the subnet VLAN. And the DHCP server can continue
to use its existing scopes.
As always, remember to apply the appropriate ACLs to VLANs on infrastruc-
ture devices if you have selected the ACL option for access control.
Setting up Helper Addresses.
If your network includes multiple VLANs,
its infrastructure devices probably already use helper addresses to forward
DHCP requests from endpoints on one VLAN to a server on another VLAN.
However you establish the quarantine subnets, the infrastructure devices now
require two helper addresses:
■
The network DHCP server’s
■
The NAC 800’s (the CS or the ES that is connected to the DHCP server)
Which device should act as the DHCP server changes as an endpoint’s integrity
posture changes. However, the NAC 800 handles this issue: it simply drops the
request if it is destined to the wrong IP address. (See Table 1-1).
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......