6-56
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 6 Configuring WLANsWireless Device Access
Configuring WLANs
posture validation is completed, the client is prompted to take action for remediation. After cleaning is
completed, the NAC appliance updates the controller to change the client state from Quarantine to
Access.
provides an example of NAC out-of-band integration.
Figure 6-27 NAC Out-of-Band Integration
In
, the link between the controller and the switch is configured as a trunk, enabling the
quarantine VLAN (110) and the access VLAN (10). On the Layer 2 switch, the quarantine traffic is
trunked to the NAC appliance while the access VLAN traffic goes directly to the Layer 3 switch. Traffic
that reaches the quarantine VLAN on the NAC appliance is mapped to the access VLAN based on a static
mapping configuration.
Follow the instructions in this section to configure NAC out-of-band integration using either the
controller GUI or CLI.
Guidelines for Using NAC Out-of-Band Integration
Follow these guidelines when using NAC out-of-band integration:
•
The NAC appliance supports up to 3500 users, and the controller supports up to 5000 users.
Therefore, multiple NAC appliances might need to be deployed.
•
CCA software release 4.5 or later is required for NAC out-of-band integration.
•
Because the NAC appliance supports static VLAN mapping, you must configure a unique quarantine
VLAN for each interface configured on the controller. For example, you might configure a
quarantine VLAN of 110 on controller 1 and a quarantine VLAN of 120 on controller 2. However,
if two WLANs or guest LANs use the same distribution system interface, they must use the same
quarantine VLAN, provided they have one NAC appliance deployed in the network. The NAC
appliance supports unique quarantine-to-access VLAN mapping.
•
For posture reassessment based on session expiry, you must configure the session timeout on both
the NAC appliance and the WLAN, making sure that the session expiry on the WLAN is greater than
that on the NAC appliance.
•
When a session timeout is configured on an open WLAN, the timing out of clients in the Quarantine
state is determined by the timer on the NAC appliance. Once the session timeout expires for WLANs
using web authentication, clients deauthenticate from the controller and must perform posture
validation again.