2-14
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 2 Preparing for Installation
Rack-Mounting Your Cisco NAC Appliance CAM/CAS
Rack-Mounting Your Cisco NAC Appliance CAM/CAS
Each Cisco NAC Appliance CAM/CAS has a set of rack handles (installed at the factory). You will use
these handles later when you install the appliance in a four-post rack. You can front (flush) mount or
mid-mount the appliance in a 19-inch (48.3-cm) equipment rack that conforms to the four-post rack
specification (the inside width of the rack should be 17.5 inches [44.45 cm]). Mount the appliance in the
brackets. When the appliance is installed in the rack, it requires one EIA 1.75-inch (4.4-cm) vertical
mounting space or 1 rack unit (RU) for mounting.
This section addresses the following two procedures:
•
Mounting the NAC-3315 Appliance in a 4-Post Rack, page 2-15
•
Mounting the NAC-3355/3395 Appliance in a Four-Post Rack, page 2-21
Caution
You must leave clearance in the front and rear of the Cisco NAC Appliance CAM/CAS to allow cooling
air to be drawn in through the front and circulated through the appliance and out the rear of the appliance.
The
Rack Installation Safety Guidelines, page 2-7
and the following information will help you plan the
equipment rack configuration:
•
When mounting an appliance in an equipment rack, ensure that the rack is bolted to the floor.
Virtual Gateway
CAUTION:
To avoid switch errors, do not connect the untrusted interface (eth1) of
a Virtual Gateway (IB or OOB) CAS to the switch until after the CAS is added to
the CAM via the web console, and VLAN mapping is configured correctly under
Device Management > CCA Servers > Manage [CAS_IP] > Advanced > VLAN
Mapping
. See the
Cisco NAC Appliance - Clean Access Server Configuration
Guide, Release 4.8(3)
for details.
•
The CAS and CAM must be on different subnets (or VLANs).
•
The trusted (eth0) and untrusted interfaces (eth1) of the CAS can have the same
IP address. (Note: this is equivalent to an L3 SVI IP address.)
•
All end devices in the bridged subnet must be on the CAS untrusted side.
•
The CAS is automatically configured for DHCP Passthrough when set to
Virtual Gateway mode.
•
Managed subnets must be configured on the CAS for all the user subnets that
are managed by the CAS. When configuring the Managed subnet, make sure
that you type an unused IP address in that subnet (for the CAS to use), and not
a subnet address.
•
Traffic from clients must pass through the CAS before hitting the gateway.
•
When the CAS is an OOB VGW, the following also applies:
CAS interfaces must be on a separate subnet (or VLAN) from the CAM.
The CAS management VLAN must be on a different VLAN than the user or
Access VLANs.
See also “Determining VLANs For Virtual Gateway” in the
Cisco NAC Appliance
- Clean Access Server Configuration Guide, Release 4.8(3)
for further details.
Table 2-4
CAS Modes— IP addressing Considerations (continued)
CAS Mode
Comments
Содержание NAC-3310
Страница 8: ...Contents 6 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 ...
Страница 172: ...A 4 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 Appendix A Open Source License Acknowledgements Notices ...
Страница 176: ...Index IN 4 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 ...