<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filter out devices without AnyConnect or NAC Agent in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741595#M488517</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My customer wants to filter out devices which don't have Anyconnect or NAC Agent on them. If AC/Agent is installed, it should communicate to AD for domain logon. Otherwise device should not be able to access any resource.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To sum up, customer doesn't want any device to communicate Active directory even for logon, if it doesn't have AC or NAC Agent.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can we deal with this request?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 07 Nov 2018 19:44:12 GMT</pubDate>
    <dc:creator>ozgguler</dc:creator>
    <dc:date>2018-11-07T19:44:12Z</dc:date>
    <item>
      <title>Filter out devices without AnyConnect or NAC Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741595#M488517</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My customer wants to filter out devices which don't have Anyconnect or NAC Agent on them. If AC/Agent is installed, it should communicate to AD for domain logon. Otherwise device should not be able to access any resource.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To sum up, customer doesn't want any device to communicate Active directory even for logon, if it doesn't have AC or NAC Agent.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can we deal with this request?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 19:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741595#M488517</guid>
      <dc:creator>ozgguler</dc:creator>
      <dc:date>2018-11-07T19:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Filter out devices without AnyConnect or NAC Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741608#M488518</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;This is a chicken / egg scenario.  While we can certainly prevent the endpoint communicating with AD through enforcement such as group-based policy or ACL, the user needs to be able to communicate with AD to validate credentials.  What's more is that AC doesn't run until after the user logs into the desktop.  One way to potentially solve for this is the EAP method.  Certificate-based authentication would allow the end user to get to the desktop where AC could then run.  If the user gets to the desktop and AC doesn't run or isn't installed then the endpoint would be left with group-based policy or ACL in place until AC was provisioned.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;-Tim</description>
      <pubDate>Wed, 07 Nov 2018 20:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741608#M488518</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-11-07T20:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Filter out devices without AnyConnect or NAC Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741611#M488520</link>
      <description>&lt;P&gt;Thanks Tim&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you mean EAP Chaining with AC? Or directly cert auth with limited access?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 20:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741611#M488520</guid>
      <dc:creator>ozgguler</dc:creator>
      <dc:date>2018-11-07T20:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Filter out devices without AnyConnect or NAC Agent</title>
      <link>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741619#M488522</link>
      <description>I was thinking EAP-TLS with limited access until posture was performed.  Then CoA would provide full access.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;-Tim&lt;BR /&gt;</description>
      <pubDate>Wed, 07 Nov 2018 20:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/filter-out-devices-without-anyconnect-or-nac-agent/m-p/3741619#M488522</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-11-07T20:26:52Z</dc:date>
    </item>
  </channel>
</rss>

