Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 55

CAS Mode IP Addressing Considerations, CAS Mode, Comments

Page 55 highlights

Chapter 2 Preparing for Installation Preparing Your Site for Installation Table 2-3 CAS Configuration Utility Worksheet c. Default gateway IP address for eth0 interface: d. IP address for eth1 interface (untrusted): e. Subnet mask (IP netmask) for eth1 interface: f. Default gateway IP address for eth1 interface 1: g. Host name for your CAS: h. IP address of Domain Name Server on your network: i. Master secret: Note The master secret must be the same for CAMs/CASs deployed as HA peers. j. Date, time and timezone: k. To generate the required temporary SSL certificate (you can change this at a later time): FQDN or eth0 IP address of CAS: Organization unit (e.g. Sales) Organization name (e.g. Cisco) Organization location (e.g. San Jose, CA, US) Note If using FQDN, make sure your DNS server is set up for the domain name. l. Root user password: m. Web console password 2: 1. eth0 and eth1 generally correlate to the first two network cards-NIC 1 and NIC 2-on the server hardware. 2. Cisco highly recommends replacing default password(s) with "strong" passwords (at least 8 characters long, comprised of a combination of two characters from each of the upper- and lower-case letters, numbers, and special characters categories) CAS Mode IP Addressing Considerations Table 2-4 CAS Mode Real-IP CAS Modes- IP addressing Considerations Comments • The trusted (eth0) and untrusted (eth1) interfaces of the CAS must be on different subnets. • Add static routes on the L3 switch or router to route traffic for the managed subnets to the trusted interface of the respective CASs. • If using DHCP relay, make sure the DHCP server has a route back to the managed subnets. OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 2-13

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

2-13
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 2
Preparing for Installation
Preparing Your Site for Installation
CAS Mode IP Addressing Considerations
c.
Default gateway IP address for eth0 interface:
d.
IP address for eth1 interface (untrusted):
e.
Subnet mask (IP netmask) for eth1 interface:
f.
Default gateway IP address for eth1 interface
1
:
g.
Host name for your CAS:
h.
IP address of Domain Name Server on your network:
i.
Master secret:
Note
The master secret must be the same for
CAMs/CASs deployed as HA peers.
j.
Date, time and timezone:
k.
To generate the required temporary SSL certificate
(you can change this at a later time):
FQDN or eth0 IP address of CAS:
Organization unit (e.g. Sales)
Organization name (e.g. Cisco)
Organization location (e.g. San Jose, CA, US)
Note
If using FQDN, make sure your DNS server is set
up for the domain name.
l.
Root user password:
m.
Web console password
2
:
1.
eth0 and eth1 generally correlate to the first two network cards—NIC 1 and NIC 2—on the server hardware.
2.
Cisco highly recommends replacing default password(s) with “strong” passwords (at least 8 characters long, comprised of a
combination of two characters from each of the upper- and lower-case letters, numbers, and special characters categories)
Table 2-4
CAS Modes— IP addressing Considerations
CAS Mode
Comments
Real-IP
The trusted (eth0) and untrusted (eth1) interfaces of the CAS must be on
different subnets.
Add static routes on the L3 switch or router to route traffic for the managed
subnets to the trusted interface of the respective CASs.
If using DHCP relay, make sure the DHCP server has a route back to the
managed subnets.
Table 2-3
CAS Configuration Utility Worksheet