cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
502
Views
0
Helpful
3
Replies

NAC Timers

hany_ibrahim
Level 1
Level 1

the default session timeout timers for NAC is :

Role                          Session timeout

unauthenticated Role           Disabled

Temporary Role                    4

Quarantine Role                    4

what is the ordering of applying these roles and timers once the user try to login to the PC ?

-before authentication

-after authentication & PC meets security requirements

-after authentication & PC doesn't meets security requirements

&

3 Replies 3

Faisal Sehbai
Level 7
Level 7

Hany,

The only timer to worry about is the Temporary Role one. That is used if you're using the agent, and are missing some requirements. This time is allowed for you to remediate (by default 4 minutes) Generally customers increase that so the clients can get remediated.

The quarantine timer only applies if you're using nessus scanning, and the unauthenticated timer only for the unauthenticated role.

HTH,

Faisal

OK , but what about the ordering of excution as i listed ?

Hany,

The order is the same as you listed. When PC is unauthenticated, the unauthenticated timers apply. When it's doing posture and remediation the Temporary role timers apply. If you're doing Nessus scanning, then the Quarantine timers apply.

HTH,

Faisal

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card