<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC and subnets management in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507351#M792283</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi A,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could put in Subnet filters designating just the last octet of that big subnet to not be authenticated. Again this might or might not work since I don't have enough details to tell you one way or the other. Subnet filters are used to exempt devices from NAC'ing. Look under Filters -&amp;gt; Subnets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Sep 2010 13:10:27 GMT</pubDate>
    <dc:creator>Faisal Sehbai</dc:creator>
    <dc:date>2010-09-13T13:10:27Z</dc:date>
    <item>
      <title>NAC and subnets management</title>
      <link>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507348#M792226</link>
      <description>&lt;P&gt;Hi, excuse me I am new to NAC. Have to manage a remote /21. Cannot split more but last subnet of group must bypass NAC, keeping integrity of GW, route and /21. How can I setup this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:04:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507348#M792226</guid>
      <dc:creator>H0nizatin0</dc:creator>
      <dc:date>2020-02-21T12:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAC and subnets management</title>
      <link>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507349#M792231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi A,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAC is all about engineering the traffic so during the authentication/posture-assessment/remediation phase traffic is always flowing through the CAS. Keeping that in mind you'll have to design your traffic flow. Without more details this is about as specific as I can get &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 17:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507349#M792231</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-09-10T17:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAC and subnets management</title>
      <link>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507350#M792250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Faisal,&lt;/P&gt;&lt;P&gt;that's in fact is what I was afraid of..&lt;/P&gt;&lt;P&gt;Unfortunately I cannot split/design the traffic before the CAS. I would like to have the last /24 subnet of my /21 subnets' group exempted from authentication (It will be a bulk of servers which, of course need to autoupdate themselves,&amp;nbsp; -while their security is managed by installed agents-).&lt;/P&gt;&lt;P&gt;So, I was wondering if there is any turnaround to avoid to manually input IP and MAC of each of these machines to make them bypass the NAC.&lt;/P&gt;&lt;P&gt;(Apologies...I hope my bad English does not create more confusion on this matter)&lt;/P&gt;&lt;P&gt;Thanks in advance for your patience&lt;/P&gt;&lt;P&gt;A (H0nizatin0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 08:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507350#M792250</guid>
      <dc:creator>H0nizatin0</dc:creator>
      <dc:date>2010-09-13T08:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAC and subnets management</title>
      <link>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507351#M792283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi A,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could put in Subnet filters designating just the last octet of that big subnet to not be authenticated. Again this might or might not work since I don't have enough details to tell you one way or the other. Subnet filters are used to exempt devices from NAC'ing. Look under Filters -&amp;gt; Subnets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 13:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507351#M792283</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-09-13T13:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAC and subnets management</title>
      <link>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507352#M792317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot for the suggestion !&lt;/P&gt;&lt;P&gt;As soon as we will start the process (we are NACing so many other subnets at the moment)&lt;/P&gt;&lt;P&gt;I will post more details about the (successful) operation.&lt;/P&gt;&lt;P&gt;Thanks again for your kind and quick support&lt;/P&gt;&lt;P&gt;A (nizatino)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 07:19:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-and-subnets-management/m-p/1507352#M792317</guid>
      <dc:creator>H0nizatin0</dc:creator>
      <dc:date>2010-09-14T07:19:43Z</dc:date>
    </item>
  </channel>
</rss>

