<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Design question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-design-question/m-p/1619854#M785905</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as the thin clients are seen as standard physical clients by the CAS (so VMware is not doing anything special with MAC/IP addresses), then what you mentioned could be a valid design option.&lt;/P&gt;&lt;P&gt;The NAC Profiler in particular can be a good plus to categorize your thin clients and automatically manage the filters on the CAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Jan 2011 13:53:28 GMT</pubDate>
    <dc:creator>Federico Ziliotto</dc:creator>
    <dc:date>2011-01-14T13:53:28Z</dc:date>
    <item>
      <title>NAC Design question</title>
      <link>https://community.cisco.com/t5/network-security/nac-design-question/m-p/1619853#M785858</link>
      <description>&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman","serif";}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Hi,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Looking for some advice on Implementing NAC across the enterprise. The environment uses laptops, desktops and thin-clients (Vmware VIEW, VDI) which connect to ESX servers where the actual machines reside (running Windows 7 and Windows XP operating systems).&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;So the question is can I use NAC server to posture assess/authenticate the thin-clients users?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;STRONG&gt;This is what I am thinking:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;SPAN style="font-family: Symbol;"&gt;&lt;SPAN&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;!--[endif]--&gt;NAC – OOB would not be supported in this design since the ESX connection to the switch would be a trunk link. Also the thin-client connection to the switch also always stays up.&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;SPAN style="font-family: Symbol;"&gt;&lt;SPAN&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;!--[endif]--&gt;NAC – Inband would be supported but could potentially be a bottle neck because the customer has a 10 gig backbone network.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;STRONG&gt;I am thinking if I can use two different NAC appliances as part of the solution. &lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;SPAN style="font-family: Symbol;"&gt;&lt;SPAN&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;!--[endif]--&gt;Use one appliance in Inband mode and use it for the ESX servers. Use the profiler to exempt the thin-clients from authentication since they basically have nothing running on them and they cannot authenticate to the NAC server.&lt;/P&gt;&lt;P class="MsoListParagraph" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;SPAN style="font-family: Symbol;"&gt;&lt;SPAN&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;!--[endif]--&gt;The second NAC appliance will be configured as Out of Band and all the remaining regular users (with physical laptops, desktops) gets authenticated to this NAC server.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;This way the NAC bottleneck would only be limited to the thin-clients users who connect to the VM’s running on the ESX server.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Is this a viable option for NAC’ing the VM clients running on ESX servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-design-question/m-p/1619853#M785858</guid>
      <dc:creator>smhussain</dc:creator>
      <dc:date>2020-02-21T12:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Design question</title>
      <link>https://community.cisco.com/t5/network-security/nac-design-question/m-p/1619854#M785905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as the thin clients are seen as standard physical clients by the CAS (so VMware is not doing anything special with MAC/IP addresses), then what you mentioned could be a valid design option.&lt;/P&gt;&lt;P&gt;The NAC Profiler in particular can be a good plus to categorize your thin clients and automatically manage the filters on the CAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 13:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-design-question/m-p/1619854#M785905</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-14T13:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Design question</title>
      <link>https://community.cisco.com/t5/network-security/nac-design-question/m-p/1619855#M785935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes the thin-clients will be seen as standard devices on the network.&lt;/P&gt;&lt;P&gt;Each Virtual Machines running on VMware ESX server (that the thin-clients will connect to) will also have unique MAC and IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Syed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Jan 2011 17:06:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-design-question/m-p/1619855#M785935</guid>
      <dc:creator>smhussain</dc:creator>
      <dc:date>2011-01-15T17:06:50Z</dc:date>
    </item>
  </channel>
</rss>

