1-41
Overview of the ProCurve NAC 800
Deployment Methods
5.
Send DHCP traffic to the NAC 800. Either:
•
Have RDAC on your DHCP server send DHCP traffic to the NAC 800.
•
Send mirrored traffic if you did not install RDAC on you DHCP server.
–
Connect the NAC 800’s port 2 to the same switch to which the
DHCP server is connected. Make the NAC 800’s switch port the
mirror port, and the DHCP server’s port the monitored port.
–
If you cannot connect the NAC 800’s port 2 to the DHCP server’s
switch, you must set up remote mirroring. For instructions on
setting up this capability on a ProCurve Switch 3500yl/5400zl/
6200yl Series, see the
Management and Configuration Guide for
the ProCurve Series 3500yl, 6200yl, and 5400zl Switches
.
6.
Throughout the network, set up the guest VLAN (for not-yet-tested end-
points) and the quarantine VLAN:
a.
Configure the appropriate VLAN ID for each integrity posture:
–
If you are using IDM, create policy group rules to match the
Unknown, Fail, and Infected postures to the profile with the
appropriate VLAN assignment.
See the
ProCurve Identity Driven Manager Users’ Guide
.
–
If you are not using IDM, set the VLAN IDs in the
/etc/raddb/
SAFreeRadiusConnector.conf
file on the NAC 800.
b.
If the VLANs selected for untested or failed endpoints do not yet exist,
create them on network infrastructure devices such as routers and
switches. Apply ACLs to restrict traffic routed in and out of the
VLANs.
c.
Create DHCP scopes for the guest and quarantine VLANs. Specify the
NAC 800 as the DNS server.
7.
Set up NAC policies and testing methods.
See the
ProCurve Network Access Controller 800 Users’ Guide
.
Deploy a NAC 800 That Provides Endpoint Integrity Only.
For a NAC
800 that enforces endpoint integrity with the 802.1X quarantine method, but
relies on IAS to authenticate users, follow these steps:
1.
Install the NAC 800, connecting its ports as follows:
•
RDAC deployment
—If you will install RDAC on your DHCP servers,
simply connect port 1 on the NAC 800 to any port in your production
network, determining the location just as you would for any RADIUS
server. You will not use the second port on the NAC 800.
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...