3-26
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 3 Installing the Clean Access Manager and Clean Access Server
Installing the Clean Access Server
At the prompt, type the eth0 IP address of the CAS and press Enter. Note that the eth0 IP address of the
CAS is the same as the Management IP address. At the confirmation prompt, type
y
to accept the entry
or type
n
to change it and enter another address for the trusted eth0 network interface. When prompted,
press Enter to confirm the value.
Note
The eth0 IP address of the CAS is the same as the Management IP address.
Step 8
Type the subnet mask of the eth0 interface or press Enter to accept the default of 255.255.255.0. Confirm
the value at when prompted.
Please enter the netmask for the interface eth0 []: 255.255.255.0
You entered 255.255.255.0, is this correct? (y/n)? [y]
Step 9
Accept the default gateway address or enter a default gateway for the eth0 address of the CAS. Confirm
the default gateway at the prompt.
Please enter the IP address for the default gateway []: 10.201.240.1
You entered 10.201.240.1 Is this correct? (y/n)? [y]
Step 10
At the Vlan Id Passthrough prompt, type
n
and press Enter (or just press Enter) to keep VLAN ID
passthrough disabled as the default behavior of the CAS. By default, VLAN IDs are stripped from traffic
passing through the interface to the CAS. Typing
y
enables VLAN IDs to be passed through the CAS for
traffic from the trusted to the untrusted network.
[Vlan Id Passthrough] for packets from eth0 to eth1 is disabled.
Would you like to enable it? (y/n)? [n]
Note
•
In most cases, enabling VLAN ID passthrough is not needed. Only enable VLAN ID passthrough if
you are sure you need it. If you choose not to enable it at this time, you can always change this option
later from the CAS
Network > IP
page of the web console or using the
service perfigo config
utility. Note that either method requires a reboot of the CAS.
•
Faulty VLAN settings can render the Clean Access Server unreachable from the Clean Access
Manager, so use caution when configuring VLAN settings.
By default, the VLAN ID is not passed through, that is, the VLAN ID is stripped from packets passed
through the CAS, as illustrated in
Figure 3-6
. The IDs are retained by the Clean Access Server and
attached to response messages passed from the untrusted network back to the trusted network.
Содержание NAC-3310
Страница 8: ...Contents 6 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 ...
Страница 172: ...A 4 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 Appendix A Open Source License Acknowledgements Notices ...
Страница 176: ...Index IN 4 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 ...