Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

How to configure NAC to automatically direct the user to the untrusted interface of CAS.

Hello,

Just want to clear how can I configure the NAC to direct the user to the untrusted interface of CAS automatically.

Now, I am manually entering the ip of the untrusted interface to my internet explorer before I can have NAC agent to download.

How can I direct the internet explorer to  the untrusted interface of the CAS without manually entering the ip address of the CAS untrusted interface?

thank you and best regards.

2 REPLIES

Re: How to configure NAC to automatically direct the user to the

Hi,

In a properly designed NAC setup, this should happen automatically. For example if your setup is L2 (the CAS can see the ARP traffic from your clients) then when you browse to any site, the traffic should hit the untrusted interface of the CAS and that should prompt a redirection page. If it's L3 and multiple hops away, then you have to use either PBRs to force the traffic to the untrusted interface of the CAS or use ACLs in certain scenarios.

If you're able to get to the network or internet from your untrusted subnets without the CAS prompting you, then there is another route for the traffic to take and you will have to troubleshoot from that angle.

HTH,

Faisal

New Member

Re: How to configure NAC to automatically direct the user to the

IC. Thanks. So If I have 4 routers to reach the untrusted interface of CAS should I configure the 4 routers of PBR.?

258
Views
0
Helpful
2
Replies