<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic mac based security managed centrally (Acs or whatever) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425403#M428189</link>
    <description>&lt;P&gt;I have a project My customer &lt;/P&gt;&lt;P&gt; want to use Mac Address based Security on their whole network.They want only specific mac addressed  pc/notebooks can be connected to  their network.But they dont want configuration per switch basis.They wan centralized management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We first looked for ACS.But we realized that ACS supports only Wireless access point for this kind of  purpose.I also found that there is a ACS feature called NAR(Network Access Restriction) Can i use this feature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They don&amp;#146;t want  additional integratio n(Active directory or etc.) and don&amp;#146;t install any software to their pc/notebooks.Because of this i cant use EAP solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They have app 300 pc&amp;#146;s and they will enter whole mac address list to ACS and only this PC&amp;#146;s will be connect to network.Is it possible ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:22:28 GMT</pubDate>
    <dc:creator>serust2003</dc:creator>
    <dc:date>2019-03-10T21:22:28Z</dc:date>
    <item>
      <title>mac based security managed centrally (Acs or whatever)</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425403#M428189</link>
      <description>&lt;P&gt;I have a project My customer &lt;/P&gt;&lt;P&gt; want to use Mac Address based Security on their whole network.They want only specific mac addressed  pc/notebooks can be connected to  their network.But they dont want configuration per switch basis.They wan centralized management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We first looked for ACS.But we realized that ACS supports only Wireless access point for this kind of  purpose.I also found that there is a ACS feature called NAR(Network Access Restriction) Can i use this feature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They don&amp;#146;t want  additional integratio n(Active directory or etc.) and don&amp;#146;t install any software to their pc/notebooks.Because of this i cant use EAP solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They have app 300 pc&amp;#146;s and they will enter whole mac address list to ACS and only this PC&amp;#146;s will be connect to network.Is it possible ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425403#M428189</guid>
      <dc:creator>serust2003</dc:creator>
      <dc:date>2019-03-10T21:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: mac based security managed centrally (Acs or whatever)</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425404#M428191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I wouldnt recommend this as a strong security solution, but it could be done - in theory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customers devices need to be configured to initiate a PAP authentication using pre-configured credentials (a'la NAC auth bypass).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS will have this username+password configured plus a network access restriction that lists the allowed set of macaddrs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While this may work for 300 users, NARs are not that easily scalable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2005 09:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425404#M428191</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2005-11-15T09:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: mac based security managed centrally (Acs or whatever)</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425405#M428192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same requirement, given that the ACS solution above is not going to be scalable enough for my requirements would you suggest I look at deploying NAC using the existing Cisco infrastructure with ACS and installing Cisco Trust Agent on all connected PCs and Notebooks with MAC authentication (switchport security) on any other devices such as printers etc?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2005 20:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425405#M428192</guid>
      <dc:creator>andyirving</dc:creator>
      <dc:date>2005-11-22T20:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: mac based security managed centrally (Acs or whatever)</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425406#M428193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This will depend if you can get the switch to issue some form of AAA request prior to allowing packets to flow from the newly connected port.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can then it should be possible to get ACS to perform some form of MAC authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the first problem is getting the switch to perform some kind of authetnication using RADIUS or T+.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2005 09:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-based-security-managed-centrally-acs-or-whatever/m-p/425406#M428193</guid>
      <dc:creator>andrewclymer</dc:creator>
      <dc:date>2005-11-23T09:11:22Z</dc:date>
    </item>
  </channel>
</rss>

