A customer directed a question when we presented Cisco NAC today. They were wondering, lets say, a Cisco NAC agent installed client connects to the network switch. It has all the valid applications and patch levels on his/her machine (posture validation checks pass)
However, even if the client passes all the posture check parameters, they would like to know that if the hostname of the client (mostly Windows Laptops) does not exist in their asset database (this database is an asset number database which is in a .csv or similar format) the posture validation should fail.
Have you encountered such request like this before ? Is there a feature on NAC server which checks a field against an external database such as an asset database ?
Currently that is not possible. You can create checks which can check for values locally, but not against external datastores, so to map this against your thought, NAC would have to know of all the workstation names before hand and then check against that. This is unwieldy and very very difficult to scale.
If this is something you and your client think would be a good addition (and it sounds like a good idea) please engage with your account team and ask them to file a Feature request for you.