Wireless (General)

  • 1.  NAC Gateway - IP Resolution Possibilities

    Posted 01-31-2017 13:58

    Analysing recurring MAC-to-IP Resolution problems in conjunction with EXOS Switches...

    SecureStacks switches seems to be easier to handle regarding this topic - maybe of the existing nodealias functionality ...

    My question is:
    what does "Always Use Fully Trusted DHCP IP" ??
     

    RackMultipart20170131-115706-1yr3wam-Always-Use-Fully-Trusted-DHCP-IP_inline.png

     


    Unfortunately no online Help - no manual - no GTAC KB

    Anybody knows that feature ??

    PS: These solve my problems basically:
    https://extremeportal.force.com/ExtrArticleDetail?an=000066216

    Regards

     



  • 2.  RE: NAC Gateway - IP Resolution Possibilities

    Posted 01-31-2017 15:11
    Hi Matthias,

    I believe "Always Use Fully Trusted DHCP IP" means that the NAC needs to be able to see both sides of the DHCP conversation. Instead of just seeing the DHCP Request that is seen from IP Helper Addresses, NAC would also need to see the offers and informs afterwards. This is typically accomplished with either a port mirror, promiscuous mode in VMware, or via policy mirror for DHCP traffic.

    Thanks,

    Tyler