<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Implementation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158512#M764086</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if your NAC appliance is more than 1 hop away from your vpn appliance, you can policy route the VPN ip pool through the NAC servers. all other traffic will be routed normally, w/o going through NAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 21 Feb 2009 02:29:59 GMT</pubDate>
    <dc:creator>srue</dc:creator>
    <dc:date>2009-02-21T02:29:59Z</dc:date>
    <item>
      <title>NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158508#M764082</link>
      <description>&lt;P&gt;We terminate vpn users on an ASA.  That is working. The problem is running the remote users through the NAC appliance while not checking other traffic.  We have tried restricting all vpn users to a vlan to layer 3 with PBR.  None of these options seem to work.  What is the best way to run remote users through NAC before allowing access to the network???  Layer 3, Layer 2, InBand, Out of Band, or ??? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158508#M764082</guid>
      <dc:creator>ursshared</dc:creator>
      <dc:date>2020-02-21T11:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158509#M764083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The recommended way to run your VPN users through the NAC appliance(s) is to  implement the L3 InBand deployment.&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;-mc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 19:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158509#M764083</guid>
      <dc:creator>maximcasseus</dc:creator>
      <dc:date>2009-02-20T19:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158510#M764084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will this work having the remote users restricted to one vlan on the ASA separate from my inside interface? Or will all traffic have to pass through the nac and exempt everything but the vpn traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 20:02:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158510#M764084</guid>
      <dc:creator>ursshared</dc:creator>
      <dc:date>2009-02-20T20:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158511#M764085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes and yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you're only inserting the NAC appliance into the existing traffic flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic you want to interrogate can be specified via your manage subnets list as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if your vpn is not setup yet, you should get it up and working through that dedicated interface and then insert the NAC appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 22:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158511#M764085</guid>
      <dc:creator>maximcasseus</dc:creator>
      <dc:date>2009-02-20T22:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158512#M764086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if your NAC appliance is more than 1 hop away from your vpn appliance, you can policy route the VPN ip pool through the NAC servers. all other traffic will be routed normally, w/o going through NAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Feb 2009 02:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1158512#M764086</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-02-21T02:29:59Z</dc:date>
    </item>
  </channel>
</rss>

