
1-52
Overview of the ProCurve NAC 800
Deployment Methods
■
Static routes
—This option relies on the NAC 800 to impose controls on
the quarantine subnet.
When you select this option, the NAC 800 omits the default gateway
address from DHCP configurations sent to quarantined endpoints; the
NAC 800 also sets the subnet mask to 255.255.255.255. (The NAC 800 does
so no matter what you specify for the gateway address and subnet mask
in the quarantine area configuration.) Isolated in its own subnet without
a gateway, the endpoint cannot transmit traffic.
As part of the DHCP configuration, the NAC 800 sends a static route to
itself, which allows the endpoints to send it DNS requests. The NAC 800
also acts as a proxy Web server for quarantined endpoints, allowing them
to reach accessible services when they request them.
The static route access control option offers easy setup: you do not have
to configure any device except for the NAC 800, and the NAC 800 auto-
matically enables access to all services required to for endpoints to update
patches and so forth. Adding another service is also easy: simply add it to
the list in the
Home
>
System configuration
>
Accessible services
window. (See Chapter 3: “System Configuration” of the
ProCurve Network
Access Controller 800 Users’ Guide
.)
Designing the Quarantine Subnet
As you should now understand, the quarantine subnet is a special subnet that
is tightly controlled and separated from production subnets. However, for
quarantined endpoints to reach the few resources to which they do need
access, you must include the quarantine subnet in your production network
architecture.
You have two options:
■
Configuring the quarantine subnet as a part of an existing subnet
■
Configuring the quarantine subnet using multinetting
If your network’s DHCP servers must receive requests from VLANs not their
own, you must set up helper addresses.
Configuring the Quarantine Subnet as Part of an Existing Subnet.
Your network probably already includes several production (or user) VLANs,
each with its own subnet. However, users might not require every available IP
address in a subnet. A good network design often reserves certain addresses
in each subnet for future use. You can now exploit those reserved IP addresses
for a quarantine subnet.
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...