HP 3350 - Cisco NAC Appliance Spezifikationen Seite 104

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 103
3-14
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 3 Switch Management: Configuring Out-of-Band Deployment
Configure Your Switches
Note If configuring the CAS as an OOB Virtual Gateway, do not connect the untrusted interface to the switch
until VLAN mapping has been configured correctly under Device Management > CCA Servers >
Manage [CAS_IP] > Advanced > VLAN Mapping. See the Cisco NAC Appliance - Clean Access
Server Configuration Guide, Release 4.9(x) for details.
Configure Your Switches
This section describes the steps needed to set up switches to be used with Cisco NAC Appliance
Out-of-Band.
Configuration Notes, page 3-14
Example Switch Configuration Steps, page 3-15
OOB Network Setup/Configuration Worksheet, page 3-21
List of MIBs and OIDs, page 3-22
Configuration Notes
The following considerations should be taken into account when configuring switches for OOB:
Because Cisco NAC Appliance OOB can control switch trunk ports, ensure the uplink ports for
managed switches are configured as “unmanaged” ports after upgrade. This can be done in one of
two ways:
Before upgrade, change the Default Port Profile for the entire switch to “unmanaged” (see
Config Tab, page 3-63).
After upgrade, change the Profile for the applicable uplink ports of the switch to “unmanaged”
(see Ports Management Page, page 3-54).
This will prevent unnecessary issues when the Default Port Profile for the switch has been
configured as a managed/controlled port profile.
Cisco NAC Appliance OOB supports 3750 StackWise technology. With stacks, when MAC
notification is used and there are more than 252 ports on the stack, MAC notification cannot be
set/unset for the 252nd port using the CAM. There are two workarounds:
Use linkup/linkdown SNMP notifications only
If using MAC notification, do not use the 252nd port and ignore the error; other ports will work
fine
Switch clusters are not supported. As a workaround, assign an IP address to each switch.
The ifindex persistence must be enabled on the switches. You can configure it by using the following
command:
(config)# snmp ifmib ifindex persist
Cisco recommends turning on portfast on access ports (those directly connected to client machines).
Cisco recommends setting the mac-address aging-time to a minimum of 3600 seconds.
On some models of Cisco switches (e.g. 4507R, IOS Version 12.2(18) EW), the MAC address(es)
connected to a particular port may not be available after Port Security is enabled.
Seitenansicht 103
1 2 ... 99 100 101 102 103 104 105 106 107 108 109 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare