<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC and DOT1X in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3189028#M555567</link>
    <description>&lt;P&gt;A Cisco NAD (switch, AP or remote access VPN device) can talk to an Authentication server using either RADIUS or TACACS. If your AD server has the NPS role then it can also be the RADIUS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to know more about Aruba then you are best asking at airheads (their community) - not the Cisco community.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Sep 2017 13:12:53 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-09-25T13:12:53Z</dc:date>
    <item>
      <title>NAC and DOT1X</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3188636#M555559</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am confused about NAC and 802.1x. What NAC is doing, what dot1x is doing. How they are related to each other. Totally confuded. Please shed some light&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3188636#M555559</guid>
      <dc:creator>gauravpundir231</dc:creator>
      <dc:date>2020-02-21T18:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAC and DOT1X</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3188653#M555561</link>
      <description>&lt;P&gt;NAC or Network Access Control is a general term describing the concept of using technical means to control network access for wired, wireless and VPN network devices and clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;802.1x is a specific technology used to implement the communications between a supplicant (software on the endpoint OS) and the network access device (NAD - switch or WLC/AP). It works in conjunction with RADIUS (between the NAD and the back end RADIUS server - e.g. ISE or ACS in Cisco products) to accomplish some of the tasks necessary for a full-fledged NAC solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/IEEE_802.1X" target="_blank"&gt;https://en.wikipedia.org/wiki/IEEE_802.1X&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2017 15:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3188653#M555561</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-09-24T15:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: NAC and DOT1X</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3188664#M555563</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;+5 Marvin.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;I was having the same confusion when I started and managed to reorder things as follow:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;NAC is the umberalla made of multiple components to provide authenticated access to the network. This access can be over wired, wireless or VPN connection.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;The NAC umberalla is composed of:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="margin-left: .75in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;Supplicant - This is the actual client connecting to the network&amp;nbsp;(windows, MACOSX, AnyConnect)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;Authenticator - This is the network device (NAD)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;Authentication Server - ISE Server, Microsoft NPM, Cisco ACS, etc&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;Identity Store - AD, RSA Token Server&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;In each access request to the network, there are 3 communications involved:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;- Communication between supplicant and authenticator (this is using dot1x protocol)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;- Communication between authenticator and authentication server (this is using radius protocol)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;&lt;SPAN style="font-family: Calibri; font-size: 11.0pt;"&gt;- Communication between authetication server and identity store (the can be LDAP, Novell, ADLDS, local inside the authentication server)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2017 17:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3188664#M555563</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2017-09-24T17:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: NAC and DOT1X</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3189022#M555564</link>
      <description>&lt;P&gt;Thanks for your rply.&lt;/P&gt;&lt;P&gt;Need more clarification.&lt;/P&gt;&lt;P&gt;So AD is actual thing that is containing the user database. Is there any possibility we can connect Authenticator directly with AD and wht is role of Authentication server (as it is just passing the info between AD and Authenticator)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, if you have any info/docs/knowldg about Aruba NAC solutions pls share as we are using it in our infra.&lt;/P&gt;&lt;P&gt;Do Aruba has different servers that authenticate users which eliminate the need of any backend database like AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 13:06:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3189022#M555564</guid>
      <dc:creator>gauravpundir231</dc:creator>
      <dc:date>2017-09-25T13:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAC and DOT1X</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3189028#M555567</link>
      <description>&lt;P&gt;A Cisco NAD (switch, AP or remote access VPN device) can talk to an Authentication server using either RADIUS or TACACS. If your AD server has the NPS role then it can also be the RADIUS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to know more about Aruba then you are best asking at airheads (their community) - not the Cisco community.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 13:12:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-and-dot1x/m-p/3189028#M555567</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-09-25T13:12:53Z</dc:date>
    </item>
  </channel>
</rss>

