I m planning to implement NAC INBand virtual mode,as if i have HP and cisco switches in my network,I have read the installation guide and cisco press book for NAC,as if now i want confirmation from you'll experts the step by step procedure to setup NAC,
As i thought to post because many of you'll have implemented NAC for several times so the general steps to start,as i m going to do antivirus update and windows update for the host posture assessment,
NAC in Inband L2 Virtual mode
About my thinking for Implementation is :
create authentication vlan on access switches,(no SVI for authentication vlan)
Do authentication mapping and actual user vlan mapping in NAC,
create a rule such as windows update and antivirus update and then requirement is to access the antivirus server and windows update server,
allow Access-list for all the user vlan to go these antivirus and windows update server BUT these ip's will be the actual vlan IP subnet because we will not have any authentication subnet in DHCP ??????? Correct me if i m wrong.
Shift the users from actual vlan to authentication vlan,
Configure managed subnet for the reply of DHCP request
Enable L3 and setup static routes
Manually go on each and every PC to open a browser so that it will be redirected to install NAC agent, IS THERE any other way TO INSTALL NAC AGENT IN 1000 WINDOWS MACHINE, MINE SYSTEM ADMINISTRATOR ARE NOT VERY SMART,SO PLEASE ANY SOLUTION WITHOUT ANY HELP OF SYSTEM ADMINISTRATOR?????? IT WILL BE HIGHLY APPRECIABLE.
The point above i have worte,, that is what i think NAC is any other point's if i m missing please plese please advice me.or give proper guidance.
4. For a L2 VGW setup (assuming In-Band), you will only have one set of IP addresses to work with, and those would be the Access VLAN IP addresses. You don't get a different IP address in your Auth VLAN. You can limit the resources you want your clients to have access to by tweaking the Traffic Policies
5. You would map the users, and you do that by defining the VLAN mappings
6. For L2 deployments, you will need managed subnets for all the IP subnets that you work with.
7. You don't need static routes for L2 deployments
8. If your clients are using any managed software system, like GPOs using AD, or SMS, or Altiris, you can push out the agent to them using those mechanims.
I need ur help once more i have read integrating windows AD users with NAC but i m not confident.what are the proper steps i have to follow for integrating as it seem very difficult for me, and also i want a SSO for login.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :