Where do the Cisco Clean Access Servers Fit in the Network?
There is a management server, known as Clean Access Managerwhich provides the administration of the Cisco Clean Access-protected network. The enforcement servers are known as Clean Access Servers. We are configuring a pair of Clean Access Servers for every 1500 network ports. The Clean Access Servers receive the validation instructions from the Clean Access Manager and download these to each client installed on workstations which connect to the network. We have configured the Clean Access Servers as routers in the university network. Access to the network is controlled via access control lists on the router. Thus, unauthenticated access is limited to very few network addresses; once authenticated and validated, Cisco Clean Access modifies the access controls to allow full access to the network.