Hello,
This one is a standart customer request before they purchasing NAC.
Sure you can connect both LAN and Gateway enforcer on a Single SEP Manager.
When client fails his VLAN changed to quarantine vlan. On quarantine vlan user just access to Gateway enforcer appliance to get remediate or get on demand agent if he hasn't nac agent,when it remediates it self lan enforcer get him back to other VLAN.
Regards,
Oykun