<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco NAC Server and Asset Number Check ? Would it work ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387283#M797792</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Short answer is no. Longer explanation is that currently CAS only authenticates users and not computers. You can however create custom checks which can check for the existence of Registry keys and/or files on the filesystem, so you could theoratically create a registry key to be deployed on all your assets and then check through NAC for its existence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for computer authentication with NAC, this is in the works but a little ways off right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Feb 2010 16:52:14 GMT</pubDate>
    <dc:creator>Faisal Sehbai</dc:creator>
    <dc:date>2010-02-26T16:52:14Z</dc:date>
    <item>
      <title>Cisco NAC Server and Asset Number Check ? Would it work ?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387282#M797756</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A customer directed a question when we presented Cisco NAC today.&amp;nbsp; They were wondering, lets say, a Cisco NAC agent installed client connects to the network switch. It has all the valid applications and patch levels on his/her machine (posture validation checks pass)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, even if the client passes all the posture check parameters, they would like to know that if the hostname of the client (mostly Windows Laptops) does not exist in their asset database (this database is an asset number database which is in a .csv or similar format) the posture validation should fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you encountered such request like this before ? Is there a feature on NAC server which checks a field against an external database such as an asset database ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387282#M797756</guid>
      <dc:creator>dumlutimuralp</dc:creator>
      <dc:date>2020-02-21T11:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC Server and Asset Number Check ? Would it work ?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387283#M797792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Short answer is no. Longer explanation is that currently CAS only authenticates users and not computers. You can however create custom checks which can check for the existence of Registry keys and/or files on the filesystem, so you could theoratically create a registry key to be deployed on all your assets and then check through NAC for its existence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for computer authentication with NAC, this is in the works but a little ways off right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 16:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387283#M797792</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-02-26T16:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC Server and Asset Number Check ? Would it work ?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387284#M797816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for the expression however I am not talking about any kind of computer authentication stuff. Like you have mentioned, the things is, eventually, when a computer name is set on an end station that hostname goes into registry key. Lets say I pull that string from registry and copy that number and check it against an external database ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dumlu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 16:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387284#M797816</guid>
      <dc:creator>dumlutimuralp</dc:creator>
      <dc:date>2010-02-26T16:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC Server and Asset Number Check ? Would it work ?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387285#M797856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dumlu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently that is not possible. You can create checks which can check for values locally, but not against external datastores, so to map this against your thought, NAC would have to know of all the workstation names before hand and then check against that. This is unwieldy and very very difficult to scale.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is something you and your client think would be a good addition (and it sounds like a good idea) please engage with your account team and ask them to file a Feature request for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 17:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-server-and-asset-number-check-would-it-work/m-p/1387285#M797856</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-02-26T17:05:03Z</dc:date>
    </item>
  </channel>
</rss>

