cancel
Showing results for 
Search instead for 
Did you mean: 

NAC Zones - design question

NAC Zones - design question

mp2014
New Contributor II
Hi,

i wanna setup NAC Zones, locations/switches being the selector. Got about 20 locations to reflect in Zones, and about 20 for dieferent endsystem classifications across all locations. Because the Zones are applied by NAC rules only, this would result in a very questionable amount of NAC rules. Ist there any other way to use zones just by switch location?
12 REPLIES 12

Rainer_Adam
New Contributor III
This should not be a big problem. I currently have about 900 rule matrix entries in my customers NAC. We there also use zones for the same reason. But zones did NOT expand your rule matrix, you have to add the zone to the users and groups AND to the rule matrix entries. Users are only viewable there (in OneView) AFTER they are authenticated with a zones fittet rule matrix. No panic about a bigger count of rules in the Rulematrix 

mp2014
New Contributor II
this article is regarding wireless zones. I'm refering to endsytem zones in nac, standard wired devices. My problem ist just the amount of NAC rules needed.
Goal is to use these zones to make only specific endsystems visible for administrator of a location.

Bharathiraja__S
Extreme Employee
Hi ,

I hope this below steps would help you to configure zones.

https://gtacknowledge.extremenetworks.com/articles/How_To/How-To-Configure-a-Location-in-NAC-For-Zon...

Thanks,
Suresh.B

GTM-P2G8KFN