<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC authentication mechanism in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051930#M5366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understood that connectivity between core swich and distribution switch is through routed port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;am i right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this is the case then intervlan routing must be done by distribution switch and have one default route pointing toward the core switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in this situation, you have to easily configure your nac with L2, inband and Virtual Gateway mode by  placing both CAS and CAM on distribution switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is the easiest way to configure NAC in your enviornment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Dec 2008 10:31:33 GMT</pubDate>
    <dc:creator>hemant1234</dc:creator>
    <dc:date>2008-12-01T10:31:33Z</dc:date>
    <item>
      <title>NAC authentication mechanism</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051929#M5363</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whether it is possible to configure the NAC with the following settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am establishing this in a campus LAN environment. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I have a Cisco 4510R Layer 3 switch as the Core switch.&lt;/P&gt;&lt;P&gt;I have Cisco 3550 Layer 3 switch as the distribution switch&lt;/P&gt;&lt;P&gt;I have some unmanaged and managed switch as the Access layer Switches. All Desktop computers are connected in this access swtich only.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Distribution Switch and core switch is connected in the Routed backbone (Trunking is not configured between Distribution and Core)&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Since I have unmanaged switches at the access layer and Core to Distribution is Routed backbone (Layer 3) i have decided to configure the NAC appliance in the following setup:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Layer 3 Inband Virtual Gateway&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I request you to provide solution and configuration steps to achieve the following:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;1.  How to configure NAC Appliance for Layer3 Inband VirtualGateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.  Users/Desktop computers should authenticate by username/password &amp;amp; Mac Address/IP address to get into the network. If the Users/Desktop computers do not match the IP address with MAC Address combination configured in the NAC appliance they should be in quarantine role. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:22:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051929#M5363</guid>
      <dc:creator>hclisschennai</dc:creator>
      <dc:date>2020-02-21T18:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication mechanism</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051930#M5366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understood that connectivity between core swich and distribution switch is through routed port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;am i right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this is the case then intervlan routing must be done by distribution switch and have one default route pointing toward the core switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in this situation, you have to easily configure your nac with L2, inband and Virtual Gateway mode by  placing both CAS and CAM on distribution switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is the easiest way to configure NAC in your enviornment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2008 10:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051930#M5366</guid>
      <dc:creator>hemant1234</dc:creator>
      <dc:date>2008-12-01T10:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication mechanism</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051931#M5367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hemant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the outset thankyou for the interest you have shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have correctly understood the scenario. Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i cannot keep the NAC at distribution layer (Edge Deployment) as i have multiple distribution switches connecting to core switch. Keeping in Distribution Switch will definitely work as you said&lt;/P&gt;&lt;P&gt;I want this it to be in Centralized Deployment. Then how the NAC (CAS) interfaces are configured. What VLAN / IP address it will be in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No document is available in Cisco to configure Layer 3 Inband Virtual Gateway Mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Dec 2008 13:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051931#M5367</guid>
      <dc:creator>hclisschennai</dc:creator>
      <dc:date>2008-12-02T13:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication mechanism</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051932#M5368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think so it is possible to have L3 Inband virtual gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Dec 2008 06:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-authentication-mechanism/m-p/1051932#M5368</guid>
      <dc:creator>nasim_nasri</dc:creator>
      <dc:date>2008-12-13T06:44:30Z</dc:date>
    </item>
  </channel>
</rss>

