1-57
Overview of the ProCurve NAC 800
Deployment Methods
Typically, however, you would not use the inline method to control a
wireless network for several reasons:
•
The Wireless Edge Services Module and ProCurve APs support 802.1X
authentication, and, for a wireless network that takes advantage of
that option, you should choose the 802.1X deployment method.
•
All traffic from the module or the APs must be forwarded through the
NAC 800 in the same VLAN.
However, some networks use an alternative such as WPA-PSK and place
all users in the same VLAN. In this case, inline quarantining might provide
a higher security option than DHCP.
Types of Access Control Provided by the NAC 800
When enforcing inline quarantining, the NAC 800 tests endpoints’ compliance
with NAC policies and controls network access according to the results.
The NAC 800 plays no role in authenticating endpoints; this service is
typically handled by the VPN gateway (or wireless AP or Wireless Edge
Service Module).
How the NAC 800 Quarantines Endpoints
With inline quarantining, the NAC 800 acts as a Layer 2 bridge that imposes a
firewall between its two ports. The NAC 800 does not forward traffic received
on port 2 out port 1 unless the source endpoint has the Healthy or Check-up
posture. And it does not forward traffic from port 1 to quarantined or unknown
endpoints.
In other words, endpoints on the port 2 side of the NAC 800 can access any
resources that are also on the port 2 side. However, they cannot access any
resources on the port 1 side until they have proved compliance with the
appropriate NAC policies.
Exceptions, as always, include the list of accessible services, which any
endpoint, no matter where it is installed and what its status, can reach.
Configuring Accessible Services for Inline Method
Because, by default, all traffic except for the testing services are blocked from
the port 1 side, you must add accessible services to allow infrastructure traffic
to traverse the bridge. For example, the NAC 800 lies inline between your LAN
and its router/VPN gateway. You want to manage the router from within the
LAN. So you must allow the management traffic in the accessible service list.
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...