<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco NAC basic install in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-nac-basic-install/m-p/1642049#M736107</link>
    <description>&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;I have bought a Cisco NAC server and a Cisco NAC manager.&amp;nbsp; I have it in the test lab at the moment but would like to roll it out to around 200 users eventually on the campus lan.&amp;nbsp; I just want it to check a user is valid on active directory.&amp;nbsp; Maybe the best way i can do this is by doing a discovery on the nac server for valid mac addresses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;Whats the best way to do this? I.e&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;user logs into a port on the campus lan&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;active directory checks they are a valid user on the domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;they get their usual dhcp address after they are authenticated&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;if they are not a valid user on the domain they will not be authenticated&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;I am not worried about checking for anti-virus, pc builds etc for now&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;At the moment i have installed both the nac server and nac manager and can access them both via a Layer 3 switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:15:24 GMT</pubDate>
    <dc:creator>ohareka70</dc:creator>
    <dc:date>2020-02-21T12:15:24Z</dc:date>
    <item>
      <title>Cisco NAC basic install</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-basic-install/m-p/1642049#M736107</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;I have bought a Cisco NAC server and a Cisco NAC manager.&amp;nbsp; I have it in the test lab at the moment but would like to roll it out to around 200 users eventually on the campus lan.&amp;nbsp; I just want it to check a user is valid on active directory.&amp;nbsp; Maybe the best way i can do this is by doing a discovery on the nac server for valid mac addresses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;Whats the best way to do this? I.e&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;user logs into a port on the campus lan&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;active directory checks they are a valid user on the domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;they get their usual dhcp address after they are authenticated&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;if they are not a valid user on the domain they will not be authenticated&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: courier new, courier; color: #000000; font-size: 10pt; mso-ansi-language: EN;"&gt;I am not worried about checking for anti-virus, pc builds etc for now&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;At the moment i have installed both the nac server and nac manager and can access them both via a Layer 3 switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-basic-install/m-p/1642049#M736107</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2020-02-21T12:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC basic install</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-basic-install/m-p/1642050#M736131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially you are asking for step-by-step guidance on how to do this. As I've just rolled out 1000 user NAC L2 VG OOB (which sounds like is what you want to do) and a 3000user NAC L3 RIP OOB as well as OOB wirless and Looking at IB VPN at the moment. My best advice would be to buy the follwoing book.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco NAC Appliance "Enforcing Host Security with Clean Access" by James Heary for about $60. (available on Amazon)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This covers ALL deployment scenarios and was invaluable to me when I set the NAC up. What it does is put in the steps needed and is easier than flitting back and forth between the CAM manual and CAS manual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 14:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-basic-install/m-p/1642050#M736131</guid>
      <dc:creator>stevek</dc:creator>
      <dc:date>2011-02-18T14:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC basic install</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-basic-install/m-p/1642051#M736150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the advice on this.&amp;nbsp; I have got a copy of the book you recommended just today and it looks quite good.&amp;nbsp; I have both the nac manager and server plugged into a layer 3 switch in the meantime just for test purposes.&amp;nbsp; I have attahced a config of what i have put in so far.&amp;nbsp; I can at least see the manager and the server on a webpage.&amp;nbsp; But i'll start looking at the book now because it will need to roll it out over Layer 2 like you did.&amp;nbsp; And if it goes well over the first 100 users we intend to roll it out to around 1500 users over the wan to replace port security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 13:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-basic-install/m-p/1642051#M736150</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2011-02-21T13:52:42Z</dc:date>
    </item>
  </channel>
</rss>

