HP 3350 - Cisco NAC Appliance Spezifikationen Seite 166

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 165
4-2
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 4 Wireless LAN Controller Management: Configuring Wireless Out-of-Band Deployment
Overview
Starting from NAC Appliance Release 4.9, the wireless OOB is supported for roaming as well. When
the client machine roams, the connectivity is not lost.
Wireless Out-of-Band is supported in the following scenarios of roaming:
Bewteen Access Points: When client roams from one Access Point to another within the same
Wireless controller (WLC).
Intra-subnet: When client roams from one WLC to another WLC, where Quarantine and Access
VLANs are the same and have the same IP subnets. WLC-2 sends SNMP Trap to CAM notifying
about the user mobility and CAM updates the database accordingly.
Inter-subnet: When client roams from one WLC to another within different subnets.
This section discusses the following topics:
Wireless In-Band Versus Out-of-Band, page 4-2
Wireless Out-of-Band Requirements, page 4-2
SNMP Control, page 4-4
Summary Steps to Configure Wireless Out-of-Band, page 4-5
Wireless In-Band Versus Out-of-Band
Table 4-1 summarizes different characteristics of each type of deployment.
Wireless Out-of-Band Requirements
Wireless Out-of-band implementation of Cisco NAC Appliance requires the following to be in place:
Cisco Wireless LAN Controllers must be supported models that use at least the minimum supported
version of IOS (supporting SNMP traps). See Table 4-2.
Cisco Wireless LAN Controllers must be Layer 2 adjacent to the Clean Access Server(s) with which
they interoperate to support wireless client login for Cisco NAC Appliance Release 4.8(1) and
earlier versions.
Table 4-1 Wireless In-Band vs. Out-of-Band Deployment
Wireless In-Band Deployment Characteristics Wireless Out-of-Band Deployment Characteristics
The Clean Access Server (CAS) is always inline
with user traffic (both before and following
authentication, posture assessment and
remediation). Enforcement is achieved through
being inline with traffic.
The Clean Access Server (CAS) is inline with user
traffic only during the process of authentication,
assessment and remediation. Following that, user
traffic does not come to the CAS. Enforcement is
achieved through the use of SNMP to coordinate
with Wireless LAN Controllers (WLCs) and to
assign/reassign VLAN assignments.
The CAS can be used to securely control
authenticated and unauthenticated user traffic.
The CAS can control user traffic during the
authentication, assessment and remediation phase,
but cannot do so post-remediation since the traffic
is Out-of-Band.
Bandwidth restricted to maximum allowable
throughput for installed Clean Access Server(s).
Out-of-Band bandwidth not restricted by Clean
Access Servers in network, as all client traffic
bypasses CASs once clients are authenticated.
Seitenansicht 165
1 2 ... 161 162 163 164 165 166 167 168 169 170 171 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare