<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC questions quick help required in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250933#M788287</link>
    <description>&lt;P&gt;kindly help me out to understand some concept of NAC as its very urgent:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) what does actually hapens before the user provide the credentials to NAC, how DHCP handle the host either NAC give it bogus ip....etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)if the user is authenticated and scanned how NAC accomodate if the have any virus after it ...in inband and out-of-band both cases?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)in OOB how server actually work on switch port, how its work, what it does ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4)is there any alert mechanism in NAC other then profiler?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5)what benefits i have if i use guest server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6)is NAC detect new system by mac-address or links-up or by dhcp request ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7)is mac spoofing for system/printer can mitigate by NAC server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8)can we only buy NAC software ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9)what is the difference b/w NAC agent,trust agent and nessus ? is cca is any other agent ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance i hope sooner reply &lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:30:23 GMT</pubDate>
    <dc:creator>sal_jam82</dc:creator>
    <dc:date>2020-02-21T11:30:23Z</dc:date>
    <item>
      <title>NAC questions quick help required</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250933#M788287</link>
      <description>&lt;P&gt;kindly help me out to understand some concept of NAC as its very urgent:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) what does actually hapens before the user provide the credentials to NAC, how DHCP handle the host either NAC give it bogus ip....etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)if the user is authenticated and scanned how NAC accomodate if the have any virus after it ...in inband and out-of-band both cases?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)in OOB how server actually work on switch port, how its work, what it does ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4)is there any alert mechanism in NAC other then profiler?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5)what benefits i have if i use guest server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6)is NAC detect new system by mac-address or links-up or by dhcp request ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7)is mac spoofing for system/printer can mitigate by NAC server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8)can we only buy NAC software ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9)what is the difference b/w NAC agent,trust agent and nessus ? is cca is any other agent ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance i hope sooner reply &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250933#M788287</guid>
      <dc:creator>sal_jam82</dc:creator>
      <dc:date>2020-02-21T11:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAC questions quick help required</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250934#M788290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.) depends on out of band vs in band deployment.  Out of band typically user is given a /30 network ip and switched once posture assessment and role assignment happen.  In band typically the standard dhcp servers give the address out and they are given a valid address.  However they are placed in a role that can be set up to restrict traffic as detailed as necessary.&lt;/P&gt;&lt;P&gt;2.) Typically nac would not be looking if the user has a virus or not but rather if the user is running AV software with the latest definitions or not&lt;/P&gt;&lt;P&gt;3.) See answer to question 1&lt;/P&gt;&lt;P&gt;7.) use profiler for that - nac will probably not help you in most situations where a user tries to bypass nac by using a different mac-address (such as whitelisted printer)&lt;/P&gt;&lt;P&gt;9.) the cca agent is software installed on a windows or linux system.  nessus is a scanning tool that can be used to do additional scanning of a device (even if not used with / before nac assessment)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 01:36:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250934#M788290</guid>
      <dc:creator>greg.washburn</dc:creator>
      <dc:date>2009-06-11T01:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAC questions quick help required</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250935#M788292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks alot for this greg.washburn for reply can you tell me from where i shuld get answer's of remaining question ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250935#M788292</guid>
      <dc:creator>sal_jam82</dc:creator>
      <dc:date>2009-06-11T14:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: NAC questions quick help required</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250936#M788297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;3) the nac server will modify the switchort vlan assignment by using snmp write&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5) it simplifies and adds more options for guest access to the network.&lt;/P&gt;&lt;P&gt;check this for much more details: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5707/ps8418/ps6128/product_data_sheet0900aecd806e98c9.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5707/ps8418/ps6128/product_data_sheet0900aecd806e98c9.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6) it can be done by either mac-address or linkup, but we usually use mac-address as when you use ip phones the switchport never goes down and up. but in both cases, a device on nac is identified by its mac address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7) to mitigate mac spoofing you have to use NAC Profiler.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; i believe you can. all you need to buy is the nac licenses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2009 14:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions-quick-help-required/m-p/1250936#M788297</guid>
      <dc:creator>halim.abouzeid</dc:creator>
      <dc:date>2009-06-12T14:00:50Z</dc:date>
    </item>
  </channel>
</rss>

