<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [NAC without authentication] in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-without-authentication/m-p/1701447#M232259</link>
    <description>&lt;P&gt;Dear All:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quick question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you implement OOB NAC but avoid using authentication. That is:&lt;/P&gt;&lt;P&gt;That is when a user tries to login through a specific port, that user (whoever it may be) is checked against a static port-assigned policy and IF the user (whoever it may be) is validated as being OK, that port will always be assigned to the same VLAN. I'm just trying to see if I can do posture validation without having user credentials on an LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;c.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:15:46 GMT</pubDate>
    <dc:creator>Carlos A. Silva</dc:creator>
    <dc:date>2019-03-11T01:15:46Z</dc:date>
    <item>
      <title>[NAC without authentication]</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-without-authentication/m-p/1701447#M232259</link>
      <description>&lt;P&gt;Dear All:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quick question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you implement OOB NAC but avoid using authentication. That is:&lt;/P&gt;&lt;P&gt;That is when a user tries to login through a specific port, that user (whoever it may be) is checked against a static port-assigned policy and IF the user (whoever it may be) is validated as being OK, that port will always be assigned to the same VLAN. I'm just trying to see if I can do posture validation without having user credentials on an LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;c.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-without-authentication/m-p/1701447#M232259</guid>
      <dc:creator>Carlos A. Silva</dc:creator>
      <dc:date>2019-03-11T01:15:46Z</dc:date>
    </item>
    <item>
      <title>[NAC without authentication]</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-without-authentication/m-p/1701448#M232285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Carlos there is a simple way to bypass authentication and just enforce posturing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However this will not work if your entire deployment requires user authentication. If not, then this is how you would accomplish this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will create device filter for all mac address and select the role type as check, reference material is found here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_addSrv.html#wp1052361"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_addSrv.html#wp1052361&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you will create a port profile and follow step 9 here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_oob.html#wp1083087"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_oob.html#wp1083087&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to know more about your deployment, please keep in mind that the filter behavior does change depending on the deployment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_addSrv.html#wp1142120"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_addSrv.html#wp1142120&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 07:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-without-authentication/m-p/1701448#M232285</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-29T07:08:39Z</dc:date>
    </item>
  </channel>
</rss>

