Users Guide

Table Of Contents
Authentication, Authorization, and Accounting 429
Network Access Control
Pre-enrollment State
In the pre-enrollment state, 802.1X/MAB clients authenticate directly with
the Network Authentication Server (NAS) as they have already completed the
enrollment process and obtained the appropriate security credentials needed
to be recognized by the Network Access Controller (NAC)/RADIUS server. As
part of the 802.1X/MAB authentication process, clients may be assigned to a
secure network or a guest network. Network security policies may be enforced
through VLANs or ACLs or a combination of both. In this context, VLANs
are used to enforce the security policy. The Dell EMC Networking switches
also support enforcement using DACLs.
For clients that are not enrolled or registered in the MAB database, the client
is authenticated into a walled garden where enrollment can be performed.
The NAC uses MAB to send an Access-Request to the RADIUS server/NAC.
The NAC must send an Access-Accept placing the unenrolled host into the
walled garden VLAN. In conjunction with placement into the walled garden,
a redirect URL and redirect ACL is included in the Access Accept to enable
enrollment via HTTP/HTTPS.
Walled Garden
The walled garden is a limited access in-band network where the client can
perform any required enrollment steps, complete posture assessment and
authenticate into the appropriate network (secure network or guest network).
A redirect-acl configuration on the NAS allows limited access to the
enrollment server along with access to a DHCP server (the client needs an IP
address) at a minimum. Other services such as NTP and DNS may also be
accessible. The NAS is configured with a redirect-url and redirect-acl to
intercept HTTP/HTTPS traffic from the client and redirect the client to the
enrollment server. Typically, a walled garden may configured in the default
VLAN or a different VLAN and a successful authentication assigns the client
to a new (secure) VLAN. The result of a successful authentication on the
enrollment server may be any one of the following: