System Administration
Working with Ranges
NOTE:
13-40
When using Extreme switches, DHCP relay IP addresses to enforce will NOT
work when the quarantine subnet is a subset of the production network. This
is because Extreme switches forward the packets from the IP address closest
to NAC 800 and not the IP address of the interface closest to the endpoint, so
all the DHCPRelay packets will appear to come from a production network
IP address.
For example, the following scenario will not work:
NAC 800 IP: 10.241.88.20
Production Network: 10.241.90.0/24
Quarantine Network: 10.241.90.160/27 (161-189 for range)
Gateway IP: 10.241.90.190
Non-Quarantine Network(s): 10.241.90.0/25, 10.241.90.128/27, 10.241.90.192/
26