1-54
Overview of the ProCurve NAC 800
Deployment Methods
■
Scope 3
Network = 10.1.4.0/24
Range = 10.1.4.25-10.1.4.125
You do not have to add quarantine subnets to the network infrastructure
because infrastructure devices include the “quarantine subnets” as part of
existing subnets.
Of course, if you have selected the ACL option for network access control,
you must apply ACLs to the production VLANs in order to control traffic from
IP addresses in the quarantine range.
The static route option can be attractive because you do not have to alter
configurations on existing infrastructure devices.
Configuring the Quarantine Subnet Using Multinetting.
With the
multinetting option, you actually add the quarantine subnets to your network
design. You might choose this option when most of the IP addresses in your
production subnets are already in use.
For example, your network might include two Class C subnets, each with
250 users:
■
192.168.8.0/24
■
192.168.12.0/24
For each existing Class C subnet, you will add new Class C subnet for the
quarantine subnet.
On the NAC 800, you set up two quarantine areas and specify one quarantine
subnet for each production subnet:
■
Area 1
Quarantine subnet = 192.168.9.0/24
Non-quarantine subnet = 192.168.8.0/24
■
Area 2
Quarantine subnet = 192.168.13.0/24
Non-quarantine subnet = 192.168.12.0/24
With this option, quarantined endpoints are placed in a truly separate subnet.
Therefore, they require a default gateway with an IP address in that subnet.
For example:
■
Area 1—Default gateway = 192.168.9.1
■
Area 2—Default gateway = 192.168.13.1
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......