[ Pobierz całość w formacie PDF ]
The PDF files and any printed representation for this material are the property of Cisco Systems, Inc.,
for the sole use by Cisco employees for personal study. The files or printed representations may not be
used in commercial training, and may not be distributed for purposes other than individual self-study.
Cisco NAC Appliance In-Band VGW Lab
Topology
Pod 1
SVI vlan 2 172.16.1.10
SVI vlan 10 10.10.1
172.16.1.1
VLAN 2
Cisco NAM
172.16.1.11 10.10.10.4
Cisco NAS
VLAN 2 VLAN 10
Manager Console
Cisco 3750
10.10.10.4
VLAN 31
VLAN 2
172.16.1.14 Cisco 2950
VLAN 31
SVI vlan 31 10.10.10.5 Client Machine
10.10.10.11
© 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 3
The figure shows the topology of the in-band VGW Cisco NAC Appliance lab.
Cisco NAC Appliance In-Band VGW SSO
Windows AD Lab Topology
Pod 1
SVI vlan 2 172.16.1.10
SVI vlan 10 10.10.1
172.16.1.1
VLAN 2
Cisco NAM
172.16.1.11 10.10.10.4
Cisco NAS
VLAN 2 VLAN 10
Manager Console &
Cisco 3750
10.10.10.4
Windows AD Server
VLAN 31
VLAN 2
172.16.1.14 Cisco 2950
VLAN 31
SVI vlan 31 10.10.10.5 Client Machine
10.10.10.11
© 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 4
The figure shows the topology of the in-band VGW SSO Windows Active Directory Cisco
NAC Appliance lab.
© 2007 Cisco Systems, Inc. Lab Guide 51
The PDF files and any printed representation for this material are the property of Cisco Systems, Inc.,
for the sole use by Cisco employees for personal study. The files or printed representations may not be
used in commercial training, and may not be distributed for purposes other than individual self-study.
Cisco NAC Appliance
In-Band VGW VPN Lab Topology
Pod 1
SVI vlan 2 172.16.1.10
SVI vlan 10 10.10.1
172.16.1.1
VLAN 2
Cisco NAM
172.16.1.11 10.10.10.4
Cisco NAS
VLAN 2 VLAN 10
Manager Console
Cisco 3750
10.10.10.4
VLAN 31
VLAN 31 10.10.10.3
VLAN 2
172.16.1.14 Cisco 2950
VLAN 100
192.168.10.3
VLAN 31
Cisco ASA
5000
SVI vlan 31 10.10.10.5 Client Machine
10.10.10.11
© 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 5
The figure shows the topology of the in-band VGW VPN Cisco NAC Appliance lab.
Cisco NAC Appliance HA In-Band
VGW VPN Lab Topology
Pod 1
SVI vlan 2 172.16.1.10
SVI vlan 10 10.10.1
172.16.1.1
Cisco NAM
HA Cluster VLAN 2
172.16.1.11 10.10.10.4
Cisco NAS
VLAN 2 VLAN 10
Manager Console &
Cisco 3750
Windows AD Server 10.10.10.4
VLAN 31
VLAN 31 10.10.10.3
VLAN 2
172.16.1.14 Cisco 2950
VLAN 100
192.168.10.3
VLAN 100
Cisco ASA
5000
SVI vlan 31 10.10.10.5 Client Machine
192.168.10.2
© 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 6
The figure shows the topology for the HA in-band VGW VPN Cisco NAC Appliance lab.
52 Implementing Cisco NAC Appliance (CANAC) v2.1 © 2007 Cisco Systems, Inc.
The PDF files and any printed representation for this material are the property of Cisco Systems, Inc.,
for the sole use by Cisco employees for personal study. The files or printed representations may not be
used in commercial training, and may not be distributed for purposes other than individual self-study.
Cisco NAM High-Availability Cluster
172.16.1.11
VLAN 2
Standby
Primary
Cisco NAM
Cisco NAM
FA 1/0/7 FA 1/0/8
Eth0 Eth0
172.16.1.12 172.16.1.13
10.100.100.3 10.100.100.4Eth1
FA 1/0/9 FA 1/0/10
Eth1
Cisco 3750
VLAN 60
10.100.100.252
© 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 7
The figure shows the topology for the Cisco NAM HA cluster, a part of the HA out-of-band
VGW Cisco NAC Appliance lab.
Cisco NAC Appliance
HA OOB VGW Lab Topology
Pod 1
SVI vlan 2 172.16.1.10
SVI vlan 10 10.10.1
172.16.1.1
Cisco NAM
HA Cluster VLAN 2
172.16.1.11 10.10.10.4
Cisco NAS
VLAN 2 VLAN 10
Manager
Console
VLAN 2, 10
10.10.10.4
Cisco 3750
VLAN 31
VLAN 2
172.16.1.14
Cisco 2950
VLAN 31
SVI vlan 2 172.16.1.28 Client Machine
10.10.10.11
© 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 8
The figure shows the topology for the HA out-of-band VGW Cisco NAC Appliance lab.
License Key
Ask your instructor for the license key.
© 2007 Cisco Systems, Inc. Lab Guide 53
The PDF files and any printed representation for this material are the property of Cisco Systems, Inc.,
for the sole use by Cisco employees for personal study. The files or printed representations may not be
used in commercial training, and may not be distributed for purposes other than individual self-study.
Cisco NAC Appliance Cabling
The following table shows the cabling and VLANs used for the entire lab.
Switch Interface Cable Type Mode VLAN Device
[ Pobierz całość w formacie PDF ]