HP 3350 - Cisco NAC Appliance Spezifikationen Seite 130

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 129
3-40
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 3 Switch Management: Configuring Out-of-Band Deployment
Configure OOB Switch Management on the CAM
Configure VLAN Profiles
You can use VLAN profiles on your Cisco NAC Appliance to resolve VLAN name-to-VLAN ID
mappings while simultaneously ensuring uniform L3 OOB support for multiple access points on your
network. VLAN profiles work in conjunction with port profiles to specify the Access VLAN for a user
session based on a set of VLAN name-to-VLAN ID mappings. If you have a single access point for
remote users on your network, VLAN profiles likely serve very little purpose. If, however, your network
includes two, three, or even dozens of different access points, VLAN profiles can help you dynamically
assign Access VLAN IDs for remote users based on a “user friendly” VLAN name assignment
associated with the user’s profile configured on the system.
When a remote user accesses the network for authentication, the Cisco NAC Appliance assigns the user
session to an Authentication VLAN before granting network access. Once the user is authenticated, the
CAM instructs the access switch (the switch through which the user is accessing the network) to assign
a VLAN ID to the managed port, based on Default Access VLAN, User Role VLAN, or Initial Port
VLAN definitions.
There are two methods to determine VLAN name-to-VLAN ID mapping criteria:
Querying local (CAM) VLAN profiles
Querying the VLAN name-to-VLAN ID maps on the access switch, itself
You can configure the CAM to query only the local database, only the switch database, or both sources
in the order you specify. When a user logs in to the network from a given access point and has been
authenticated, they may be assigned one VLAN ID for one switch and a different VLAN ID for another.
Figure 3-20 provides an example of this feature in a remote-access scenario.
Figure 3-20 VLAN Profile Feature Example
1. In the morning, user1 attempts to remotely access the network and his session arrives via switch A.
Switch A allows the user authentication-level access and user1 passes authentication credentials on
to the CAM.
2. Upon receiving the authentication request, the CAM discovers the Access VLAN for user1’s session
is defined in the associated user role, which specifies a VLAN name “VPN_access.
3. The CAM queries VLAN profile assignments for the VLAN ID corresponding to “VPN_access” and
discovers a VLAN profile associated with the port profile for Switch A indicating VLAN 5.
12
3
6
9
CAM
AM
Authentication
PM
Authentication
Switch A Switch B
Switch port assigned
to VLAN 5
Switch port assigned
to VLAN 15
user1
AM login on VLAN
"VPN_access"
user1
PM login on VLAN
"VPN_access"
183881
Seitenansicht 129
1 2 ... 125 126 127 128 129 130 131 132 133 134 135 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare