cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
715
Views
0
Helpful
2
Replies

Clean Access Agent

alex.osaw
Level 1
Level 1

What would be the pros and cons of installing the Clean Access Agent in a L2/L3 OOB scenario?

2 Replies 2

srue
Level 7
Level 7

with OOB, you can't do bandwidth throttling or apply ACLs, since once the user is authenticated properly they are out of band. (you can apply those things only to user roles such as quarantine, temporary, etc). on the other hand, the CAS is not a bottleneck with OOB either. with OOB, you'll need to roughly duplicate your LAN and dhcp scopes for the unauthorized vlans/subnets.

that's just off the top of my head.

r.bishop
Level 1
Level 1

Hi there,

A couple of other points to note about IB vs OOB:

(1) OOB will only work with Cisco switches and even then you need to check since it may not work with some older Cisco switches. With InBand (IB) the switch type is irrelevant.

(2) OOB mode can now be supported with Cisco wireless (centralised using WLC) but only if CAS has L2 connectivity to the WLC; NAC v4.5 and WLC v5.1 onwards. Originally NAC for wireless was only supported using IB mode.

This link discusses the different options that may be best suited to your environment:

http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/45/cas/s_deploy.html

Hope this helps.

Thanks

Russell

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: