ā05-17-2010 01:04 PM - edited ā02-21-2020 03:57 AM
Dear Experts,
I m planning to implement NAC INBand virtual mode,as if i have HP and cisco switches in my network,I have read the installation guide and cisco press book for NAC,as if now i want confirmation from you'll experts the step by step procedure to setup NAC,
As i thought to post because many of you'll have implemented NAC for several times so the general steps to start,as i m going to do antivirus update and windows update for the host posture assessment,
NAC in Inband L2 Virtual mode
About my thinking for Implementation is :
The point above i have worte,, that is what i think NAC is any other point's if i m missing please plese please advice me.or give proper guidance.
ā05-17-2010 07:34 PM
Hi,
1. This is correct. Auth VLANs shouldn't have SVIs anywhere on the network
2. Okay
3. Okay. For posture assessment, look at chalktalk 5 from this link: http://bit.ly/chalktalks
4. For a L2 VGW setup (assuming In-Band), you will only have one set of IP addresses to work with, and those would be the Access VLAN IP addresses. You don't get a different IP address in your Auth VLAN. You can limit the resources you want your clients to have access to by tweaking the Traffic Policies
5. You would map the users, and you do that by defining the VLAN mappings
6. For L2 deployments, you will need managed subnets for all the IP subnets that you work with.
7. You don't need static routes for L2 deployments
8. If your clients are using any managed software system, like GPOs using AD, or SMS, or Altiris, you can push out the agent to them using those mechanims.
HTH,
Faisal
ā05-21-2010 03:20 AM
hello Faisal,
It seem that u r the real Expert for NAC,
I need ur help once more i have read integrating windows AD users with NAC but i m not confident.what are the proper steps i have to follow for integrating as it seem very difficult for me, and also i want a SSO for login.
Thanks
ā05-23-2010 05:56 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: