<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC quick question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-quick-question/m-p/1173391#M742706</link>
    <description>&lt;P&gt;Hi, just trying to confirm the behavior of a NAC solution without High Availability. &lt;/P&gt;&lt;P&gt;I belive that if there's no High availability configured:&lt;/P&gt;&lt;P&gt;1. IF the CAM fails (CAS and CAM are no longer able to communicate) all new connections will  be denied, but users already certified will be allowed into the network.&lt;/P&gt;&lt;P&gt;2. If the CAS fails in In-band mode: All user traffic will be dropped as well as new connections&lt;/P&gt;&lt;P&gt;3. If the CAS fails in out-of-band mode: new connections will not be possible, but certified users will still have access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me if this is correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:27:20 GMT</pubDate>
    <dc:creator>Daniela Herrera</dc:creator>
    <dc:date>2020-02-21T11:27:20Z</dc:date>
    <item>
      <title>NAC quick question</title>
      <link>https://community.cisco.com/t5/network-security/nac-quick-question/m-p/1173391#M742706</link>
      <description>&lt;P&gt;Hi, just trying to confirm the behavior of a NAC solution without High Availability. &lt;/P&gt;&lt;P&gt;I belive that if there's no High availability configured:&lt;/P&gt;&lt;P&gt;1. IF the CAM fails (CAS and CAM are no longer able to communicate) all new connections will  be denied, but users already certified will be allowed into the network.&lt;/P&gt;&lt;P&gt;2. If the CAS fails in In-band mode: All user traffic will be dropped as well as new connections&lt;/P&gt;&lt;P&gt;3. If the CAS fails in out-of-band mode: new connections will not be possible, but certified users will still have access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me if this is correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-quick-question/m-p/1173391#M742706</guid>
      <dc:creator>Daniela Herrera</dc:creator>
      <dc:date>2020-02-21T11:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: NAC quick question</title>
      <link>https://community.cisco.com/t5/network-security/nac-quick-question/m-p/1173392#M742719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me see if I can help you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 - In general, yes.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 - Yes - the CAS in-band is a network device that all traffic flows through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3 - Yes - in Out-of-band mode, the CAM and CAS change the vlans as users enter/leave the network.  If the CAM/CAS is unavailable, no vlan changes can occur.  So ports remain on the vlan they are currently on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you have follow up questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 14:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-quick-question/m-p/1173392#M742719</guid>
      <dc:creator>pcomeaux</dc:creator>
      <dc:date>2009-05-15T14:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: NAC quick question</title>
      <link>https://community.cisco.com/t5/network-security/nac-quick-question/m-p/1173393#M742752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1- this depends on your fallback configuration. You have 3 modes:&lt;/P&gt;&lt;P&gt;*Ignore: already trusted users still have access to the network, new users are blocked. (this is the default behavior, if you don't change this setting, new users will be blocked)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Allow All: already trusted users and new users are all allowed to access the network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Block All: All users (trusted and non-trusted) are blocked (i believe this applies only in inband mode, in out of band it should behave like the ignore mode)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To change this setting go to Device Management --&amp;gt; CCA Servers --&amp;gt; Manage --&amp;gt; Filter --&amp;gt; Fallback&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 May 2009 08:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-quick-question/m-p/1173393#M742752</guid>
      <dc:creator>halim.abouzeid</dc:creator>
      <dc:date>2009-05-22T08:32:46Z</dc:date>
    </item>
  </channel>
</rss>

