Preparing For Dhcp Plug-In Installation - Extreme Networks Sentriant AG Software User's Manual

Hide thumbs Also See for Sentriant AG:
Table of Contents

Advertisement

DHCP Plug-in
If Sentriant AG can communicate with more than one DHCP server, all of the DHCP servers will
behave normally, each vending IP addresses to endpoints as prescribed by Sentriant AG. However, a
DHCP server will discontinue vending IP addresses if Sentriant AG loses communication with that
server.
If Sentriant AG can communicate with only one DHCP server, that server will be told to continue
vending IP addresses even if communication between the Sentriant AG and that DHCP server is lost.
If Sentriant AG loses communication with all DHCP servers, the associated enforcement cluster (EC)
will have its Access mode set to allow all automatically. When communication is re-established with
at least one DHCP server, the EC's Access mode will be restored to the last manually-configured
setting, either normal or allow all. For more information about an EC's Access mode, see
the Access Mode" on page
If the connection between a DHCP server and Sentriant AG is lost and re-established, the existing
ACL on the DHCP server is discarded and Sentriant AG re-transmits the entire ACL to the DHCP
server, so all DHCP servers are synchronized.
Sentriant AG attempts to connect to known DHCP servers on start-up, and continuously attempts to
connect at regular intervals indefinitely.

Preparing for DHCP Plug-in Installation

When Sentriant AG does not sit inline with the DHCP server, you need to set up a remote host for
Device Activity Capture (DAC) to allow Sentriant AG to listen on the network. This is done by
installing a small program on the DHCP server or other remote (non-Sentriant AG) host, which then
sends relevant endpoint information back to Sentriant AG.
In addition, certificates and keys must be generated for communication between Sentriant AG and each
plug-in-enabled DHCP server.
NOTE
Windows Server 2003 is the only server supported for this release.
To prepare Sentriant AG for DHCP plug-in installation:
1 The DHCP plug-in requires that you first configure your system with RDAC as described in the
"Creating a DAC Host" on page
2 Each DHCP server that has or will have the DHCP plug-in must have a certificate for
communicating with Sentriant AG. For each DHCP plug-in, do the following:
a On the Sentriant AG MS, run the following command:
MakeDHCPCert "
Where:
<dn> is your organization's distinguished name (DN) for this certificate. The common name (CN)
is the only portion of the DN that is required. It should match the fully qualified domain name
(FQDN) or IP address of the server which will use the resulting certificate. Enter this value in
quotation marks.
296
79.
239.
<dn>"
Sentriant AG Software Users Guide, Version 5.3
"Selecting

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentriant ag 5.3

Table of Contents