Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

NAC Inband Trunk on Untrusted Interface


I am query regarding inband implementation of NAC server.

Is it possible to have multiple vlans to terminate on the untrusted interface of the NAS in real gateway mode?

Is this is the case, how can  I add an IP address to each vlan ID on the untrusted interface.

The aim is to implement the following deployment.

The network architecture is a collapsed Core, Distribution/Core on the same 2 switchs with SVIs on the distribution switchs for all the vlans. Since the network may not have all cisco switchs, I am forced to use Inband deployment.

I wanted to trunk required vlans to the NAC untrusted interface, remove the SVIs on the Distribution Switchs forcing vlan clients onto the NAC.

The trusted NAC interface will be connected to a SVI vlan or L3 interface on the distribution switch.

Since the NAC is in real gateway mode, DHCP pool or DHCP relays need to configure on the NAC server as well.

As a summary, can you please advise if it is possible to create something like SVIs on the NAC untrusted port and define DHCP relay on those SVIs on the untrusted interface.