HP ProCurve NAC 800 User Manual page 205

Hide thumbs Also See for ProCurve NAC 800:
Table of Contents

Advertisement

Enforcement Mode
DHCP mode
Network
enforcement
NOTES:
• (*) The gateway does not have to be in the broadcast domain (which is good, since the netmask gives the endpoint no
real broadcast domain), as long as it is in the same (Layer 2) subnet—the router will get you there.
• (**) Allowing access to the Internet is up to the customer, but is necessary for access to any IP addresses in
Accessible services
Table 4-1.
Troubleshooting Quarantined Endpoints (cont.)
How endpoints are quarantined and
redirected to NAC 800
DHCP server (NAC 800) gives the
endpoint:
• Quarantine range IP address
• Appropriate netmask for quarantine
subnet
• Appropriate default gateway
• NAC 800 server's IP as DNS server
(will resolve everything except
Accessible services
800 IP address)
• The switch is configured with
additional IP helper addresses to
forward broadcast DHCP requests to
ESs as well as production DHCP
servers.
Switches must be configured for
multinetting (multinetting segment) so
there can be two networks on the same
physical device (or devices) that
cohabitate, but they should not be able
to talk to one another as enforced by the
switch (using ACLs). Each port on the
switch will be allowed to be on either
the production or quarantine network,
and the switch will have a secondary IP
address assigned to the gateway port
(so there will be different gateway IP
addresses for the production and
quarantine networks).
System configuration>>Cluster setting defaults area>>Accessible services
(
Troubleshooting Quarantined Endpoints
How quarantined endpoints reach
accessible devices
NAC 800 (fake root) DNS – As in
endpoint enforcement (for access to
names in Accessible services). The
DNS server forwards requests for
accessible services to a real DHCP
server for resolution.
ACLs on the switch prevent
quarantined systems from talking to
production systems, but allow for the
to the NAC
following specific traffic:
• Quarantine --> NAC 800 (OK)
• Production --> Quarantine (OK)
• Quarantine -|-> Production (NO)
• Quarantine -?-> Internet (Maybe*)
Endpoint Activity
).
4-25

Advertisement

Table of Contents
loading

Table of Contents