Inline - HP ProCurve NAC 800 User Manual

Hide thumbs Also See for ProCurve NAC 800:
Table of Contents

Advertisement

Inline Quarantine Method

Inline

9-2
Inline
Inline is the most basic NAC 800 installation. When deploying NAC 800 inline,
NAC 800 monitors and enforces all endpoint traffic. NAC 800 allows endpoints
to access the network or blocks endpoints from accessing the network based
on their Internet Protocol (IP) address with a built-in firewall (iptables).
When NAC 800 is installed in a single-server installation, NAC 800 becomes a
Layer 2 bridge that requires no changes to the network configuration settings.
As shown in (figure 9-1), NAC 800 is installed inline in a multiple-server
configuration, the multiple ESs form a Layer 2 bridge that spans two switches,
resulting in a network loop. This is an undesirable situation. To prevent this,
you may have to configure the switch that connects the NAC 800 ESs to use
Spanning Tree Protocol (STP), if STP is not already configured. The STP
automatically detects the loop, and closes one of the offending ports on the
switch based on the switch configuration. If an ES becomes unavailable, the
switch automatically reconnects the previously closed port so that there is
always a path from the VPN to an ES.

Advertisement

Table of Contents
loading

Table of Contents