09-06-2012 03:42 AM - edited 03-10-2019 07:30 PM
Dear Experts,
Is it Mandatory to have DHCP Server for NAC Deployment?
We want to deploy NAC for 500-600 users across WAN. We are planning for L3-OOB-Real Gateway central deployment Solution.
We are having one NAC Server (3355) - with 1500 users license & one NAC manger (3315) with 3 NAC Server Licnese.
Currently there is no DHCP Server in Network. All users are having Static IPs to their desktops/Laptops.
20 Remote offices are managed by ISP.
So please clarify, whether we can deploy NAC without DHCP or it is mandatory? Is it documented in cisco site ?
Please provide the prerequisites for NAC deployment.
09-06-2012 06:50 AM
Hi,
If you are doing out of band eployment then dhcp will be required, you will have to route your initial traffic through the Clean Access Server, however once the out of band feature kicks in it will move the client from the "unauthenticated" vlan to the "authenticated or trusted" vlan. Here is some documentation that will help you with the flow:
If you plan on performing L3 In Band then you are good to go, the only reason you need dhcp is because of your policy based routing where initial traffic always has to flow through the CAS.
Thanks,
Tarik Admani
*Please rate helpful posts*
09-06-2012 09:39 PM
Hi Tarik,
Thanks for your Inputs, Can you also help us with prerequisites of each NAC deployment mode.
09-06-2012 10:21 PM
Hi,
I havent come across anything written as a pre-requisite but if based on my experience working with Clean Access DHCP server is only required for the following scenarios:
Where you do not require a dhcp server:
Let me know if this makes sense.
Thanks,
Tarik Admani
*Please rate helpful posts*
09-06-2012 11:49 PM
Hi Tarik,
Thanks Again for your valuable inputs,
IN L3 OOB Real IP GW Mode, we can use CAS as a DHCP Server.
In CAS config guide it is given thatIt allocates client IP addresses for the managed (untrusted) network.
Initially When user in Untrusted network, after posture assessment user will need IP address from Trusted Network.
For this should we have separate DHCP Server ? or
Can we configure this CAS DHCP Server for trusted (Employee) network as well ?
Since we dont have a DHCP Server in network?
01-13-2014 11:09 AM
Not really ! But depends on your solution sketch up .
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide