NAC Gateway - IP Resolution Possibilities

  • 0
  • 2
  • Question
  • Updated 2 years ago
  • Answered
Analysing recurring MAC-to-IP Resolution problems in conjunction with EXOS Switches...

SecureStacks switches seems to be  easier to handle regarding this topic - maybe of the existing nodealias functionality ...

My question is:
what does "Always Use Fully Trusted DHCP IP" ??

Unfortunately no online Help - no manual - no GTAC KB

Anybody knows that feature ??

PS: These solve my problems basically:

Photo of M.Nees

M.Nees, Embassador

  • 9,568 Points 5k badge 2x thumb

Posted 2 years ago

  • 0
  • 2
Photo of Tyler Marcotte

Tyler Marcotte, Official Rep

  • 2,784 Points 2k badge 2x thumb
Hi Matthias,

I believe "Always Use Fully Trusted DHCP IP" means that the NAC needs to be able to see both sides of the DHCP conversation. Instead of just seeing the DHCP Request that is seen from IP Helper Addresses, NAC would also need to see the offers and informs afterwards. This is typically accomplished with either a port mirror, promiscuous mode in VMware, or via policy mirror for DHCP traffic.