HP 3350 - Cisco NAC Appliance Spezifikationen Seite 127

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 126
3-37
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 3 Switch Management: Configuring Out-of-Band Deployment
Configure OOB Switch Management on the CAM
Note Cisco recommends enabling this option for all Out-of-Band deployments to ensure the most
accurate status updates in the Out-of-Band Online Users list, and ensure that you do not
configure any local (CAS-based) device filters that would potentially conflict with this global
setting.
Rules configured for MAC addresses on the global Device Filter list have the highest priority for
user/device processing in both OOB and IB deployments. See Device Filters for Out-of-Band
Deployment, page 2-14 for further details.
For more information on In-Band vs. Out-of-Band client machine behavior based on specified
Device Filter type, see In-Band and Out-of-Band Device Filter Behavior Comparison,
page 2-16.
Step 10 The Change to [Auth VLAN | Access VLAN] if the device is certified, but not in the Out-of-Band
user list option is automatically enabled when a port is managed. Choose which VLAN to use when the
device is certified and the user is reconnecting to the port:
Default Auth VLAN—Force Access VLAN clients on this port to re-authenticate on the
Authentication VLAN the next time they connect to the network.
Default Access VLAN—Allow clients to stay on the trusted network without having to login again
the next time they connect to the network.
Step 11 Use the Bounce the port after VLAN is changed option to specify port behavior following VLAN
change:
For Real-IP gateways, check this box to prompt the client to get a new IP address once switched to
the Access VLAN.
For Virtual gateways, leave this box unchecked.
Note If using a version 4.1.2.0 or later Windows Agent, ActiveX Control, or Java Applet to refresh client
DHCP IP addresses, the Bounce the switch port after VLAN is changed option in the Port profile can
be left disabled. Refer to DHCP Release/Renew with Agent/ActiveX/Java Applet, page 5-6, Configure
Access to Authentication VLAN Change Detection, page 3-67, and see Advanced Settings, page 3-45
for additional details on configuring DHCP Release, VLAN Change, and DHCP Renew delays.
Step 12 When you enable the Bounce the port based on role settings after VLAN is changed option, the
switch defers to the associated user role to determine port bouncing and/or IP address refresh/renew
behavior when the VLAN of the port through which the user is accessing the network switches from the
authentication to the access VLAN. Both of the user role options are on the User Management > User
Roles > New Role page.
Note If you enable the Bounce the port after VLAN is changed option in step 11 above, this option is
inaccessible.
Step 13 You can check the Generate event logs when there are multiple MAC addresses detected on the same
switch port box to generate event logs when multiple MAC addresses are found on the same switch port.
Warning
Avoid using this option for switches with large number of Access Ports such as 6500 and 3750 stacks.
Seitenansicht 126
1 2 ... 122 123 124 125 126 127 128 129 130 131 132 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare