Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Users might experience few discrepancies in Search results. We are working on this on our side. We apologize for the inconvenience it may have caused.
New Member

Global port security (NAC or MAC?)

I am looking for a solution where a user machine is authenticated before being allowed on the system, we have many users that move about the network and patch in wherever they can. i need to restrict access onto the network but obviously standard port-security cannot be used due to the dynamic nature of our users. I have looked at 802.1x with our ACS and using the Cisco Trust Agent as the supplicant, would this work?

Another thought I had would be if the switchport could check a database of known mac addresses before allowing access onto the network.

Has anybody any ideas how to implement this, I don't think we would need all the features of NAC but maybe this is the only solution.


Re: Global port security (NAC or MAC?)

From my understaning any workstation running 802.1x compliant client software (for ex. Windows XP) can be the supplicant.

You can also look into the option of using VMPS, where the users will be put on the same VLAN based on their MAC address to VLAN mapping on the VMPS database, irrespective of which ports they are connecting to. More info on VMPS is here:

CreatePlease to create content