NAC Gateway - IP Resolution Possibilities

  • 0
  • 2
  • Question
  • Updated 2 years ago
  • Answered
Analysing recurring MAC-to-IP Resolution problems in conjunction with EXOS Switches...

SecureStacks switches seems to be  easier to handle regarding this topic - maybe of the existing nodealias functionality ...

My question is:
what does "Always Use Fully Trusted DHCP IP" ??

Unfortunately no online Help - no manual - no GTAC KB

Anybody knows that feature ??

PS: These solve my problems basically:

Photo of M.Nees

M.Nees, Embassador

  • 9,264 Points 5k badge 2x thumb

Posted 2 years ago

  • 0
  • 2
Photo of Tyler Marcotte

Tyler Marcotte, Official Rep

  • 2,740 Points 2k badge 2x thumb
Hi Matthias,

I believe "Always Use Fully Trusted DHCP IP" means that the NAC needs to be able to see both sides of the DHCP conversation. Instead of just seeing the DHCP Request that is seen from IP Helper Addresses, NAC would also need to see the offers and informs afterwards. This is typically accomplished with either a port mirror, promiscuous mode in VMware, or via policy mirror for DHCP traffic.