<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How build NAC? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694341#M833469</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Max&lt;/P&gt;&lt;P&gt;YES VPN can be used with NAC.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-thread-small" href="https://community.cisco.com/thread/237738"&gt;https://supportforums.cisco.com/thread/237738&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might have heard about the Cisco secure ACS which understands radius and tacacs+ for authentication and authorization.&lt;/P&gt;&lt;P&gt;You have mistaken something here, NAC- Network Admission Control is all about End-Point security and ACS is Identity management and security .&lt;/P&gt;&lt;P&gt;Yes NAC can have an ACS as an external database from where you can authenticate and even Authorize using another Radius Server Behind ACS.&lt;/P&gt;&lt;P&gt;So the flow goes this way. NAC--&amp;gt; ACS--&amp;gt; Radius Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/index.html"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any doubts !&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Eddy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 May 2011 20:04:01 GMT</pubDate>
    <dc:creator>edwjames</dc:creator>
    <dc:date>2011-05-16T20:04:01Z</dc:date>
    <item>
      <title>How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694338#M833466</link>
      <description>&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #fff;" title="Привет всем."&gt;Hi all. &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ebeff9;" title="у меня есть несколько вопросов."&gt;I have a few questions. &lt;/SPAN&gt;&lt;SPAN title="Я студент."&gt;I am a student. &lt;/SPAN&gt;&lt;SPAN title="Пишу диплом."&gt;I'm writing a diploma. &lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;" title="В своей работе использую оборудование Cisco."&gt;In its work, using equipment Cisco. &lt;/SPAN&gt;&lt;SPAN title="Я прошёл уровень CCNA."&gt;I passed the level of CCNA. &lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;" title="Но мне очень срочно нужно сделать макет к моей дипломной работе."&gt;But I really urgently need to do a layout for my thesis work. &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;" title="Исходные данные:"&gt;Raw data: &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="свитч Cisco 3550, на нём настроены VLAN"&gt;Cisco Switch 3550, it set up VLAN &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="роутер 2600XM, делает маршрутизацию между VLAN"&gt;Router 2600XM, makes routing between VLAN &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Имею Cisco NAC appliance running in VMware."&gt;I have the Cisco NAC appliance running in VMware. &lt;/SPAN&gt;&lt;SPAN title="Имеется сервер и manager."&gt;There is a server and manager. &lt;/SPAN&gt;&lt;SPAN title="версии 4.1."&gt;Version 4.1. &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Вопросы:"&gt;Questions: &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Если сконфигурировать через manager сервер, может ли работать сервер автономно, не имея доступа к manager?"&gt;If you configure a server manager, can run the server independently, without access to a manager? &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Шифрует ли пакеты данная технология?"&gt;Does this technology Encrypt packets ? &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Я впервые сталкиваюсь с этой технологией."&gt;It was my first encounter with this technology. &lt;/SPAN&gt;&lt;SPAN title="Мне никто не помогает."&gt;Nobody is helping me. &lt;/SPAN&gt;&lt;SPAN title="Мне необходимо, что бы на клиентском компьютере проинсталлировалась программа, которая проверит компьютер на обновлённые операционной системы."&gt;I need that would be on the client computer to install a program that checks their computer for the updated operating system. &lt;/SPAN&gt;&lt;SPAN title="Для меня очень сложно следовать материалу Cisco Guid, можете ли вы мне дать ссылку, на построение такой сети (сервер, manager, и если надо Cisco), или кратко рассказать , как это сделать?"&gt;For me it is difficult to follow the material Cisco Guid (&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;a lot&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;of material&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;an urgent need&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to make a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;working&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;model)&lt;/SPAN&gt;&lt;/SPAN&gt;, can you give me a link to build such a network (server, manager, and if need to Cisco), or briefly describe how to do this? &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Зарание спасибо."&gt;Thanks in advance. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:20:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694338#M833466</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2020-02-21T12:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694339#M833467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Max&lt;/P&gt;&lt;P&gt;Server Without manager is of No use.&lt;/P&gt;&lt;P&gt;Server only enforces, Manager manages and contains most of the configuration.&lt;/P&gt;&lt;P&gt;IPSEC Tunnels are formed between CAS and CAM.&lt;/P&gt;&lt;P&gt;The NAC agent that checks for Antivirus , etc on the Operating System Can be pushed through the CAM( The Manager) .&lt;/P&gt;&lt;P&gt;if the CAM is updated via the internet connection it will contain the latest versions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_admin.html"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_admin.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no particular document for just the configuration what you need. But keep asking whatever you dont understand.&lt;/P&gt;&lt;P&gt;Help will be provided.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 19:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694339#M833467</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-16T19:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694340#M833468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #fff;" title="Я немного растерялся."&gt;I'm a little confused. &lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Thank you&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;for providing the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;link&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;" title="Меня интересует следующее."&gt;I am interested in the following. &lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;" title="Я где-то читал, что нужно настраивать на свитче или роутере AAA авторизацию, либо что либо связанную с radius, нужно ли это делать?"&gt;I read somewhere that you need to configure switch or router AAA authorization, or that either associated with the radius, whether you want to do this? &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;" title="Моя работа магистерская предполагает новшество, что я буду использовать одновременно ассиметричное и симметричное шифрование пакетов."&gt;My master's work involves innovation that I'll be using both asymmetric and symmetric encryption packages. &lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;" title="Помимо шифрованием NAC, хотел использовать vpn, с другим шифрованием."&gt;In addition to encryption, NAC, wanted to use a vpn, with a different encryption. &lt;/SPAN&gt;&lt;SPAN title="Но мой руководитель сказал, что это глупо."&gt;But my supervisor said it was stupid. &lt;/SPAN&gt;&lt;SPAN style="background-color: #fff;" title="Как на ваш взгляд, если использовать данную иновацию?"&gt;How do you think ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 19:53:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694340#M833468</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-16T19:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694341#M833469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Max&lt;/P&gt;&lt;P&gt;YES VPN can be used with NAC.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-thread-small" href="https://community.cisco.com/thread/237738"&gt;https://supportforums.cisco.com/thread/237738&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might have heard about the Cisco secure ACS which understands radius and tacacs+ for authentication and authorization.&lt;/P&gt;&lt;P&gt;You have mistaken something here, NAC- Network Admission Control is all about End-Point security and ACS is Identity management and security .&lt;/P&gt;&lt;P&gt;Yes NAC can have an ACS as an external database from where you can authenticate and even Authorize using another Radius Server Behind ACS.&lt;/P&gt;&lt;P&gt;So the flow goes this way. NAC--&amp;gt; ACS--&amp;gt; Radius Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/index.html"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any doubts !&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Eddy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 20:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694341#M833469</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-16T20:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694342#M833470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Thanks for the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;replies&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Have any&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;more questions&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;When&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;installing&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the server&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the following questions arise&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;At the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;beginning of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the server's configuration&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Please enter the IP address for the interface eth0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;This&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;address&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;is connected&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;manager&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;server&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;The default gateway&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;should&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;point to a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;manager&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;or a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;router&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;that provides&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Internet access&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;Next. Vlan Id Passthrough for packets from eth0 to eth1 is disabled. Would you like to enable it?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;What&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;this&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;question means&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Do I need to&lt;/SPAN&gt; enable&lt;SPAN class="hps" title="Click for alternate translations"&gt; it&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;Same question.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;Management VLAN Tagging for egress packets of eht0 is disabled. Would you like to enable it?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;What&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;this&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;question means&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Do I need to&lt;/SPAN&gt; enable&lt;SPAN class="hps" title="Click for alternate translations"&gt; it&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;Please enter the IP addresses for the name servers. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;This&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;item&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;requests that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;enter the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;DNS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;server&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;After&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;installing&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the server&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; do&lt;SPAN class="hps" title="Click for alternate translations"&gt; I needed&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;any&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;further&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;configure&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;it&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;People often ask me&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;how to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;check&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Agent&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;operating systems.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;If&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the Windows&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;everything is clear&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;, then&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;how&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;is checked&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;on&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;unix&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;systems&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Is there a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;program&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;for&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;smartphones&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;, android, windows mobile ...?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Regarding&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;VPN,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I want to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;use&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;a single&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;server&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;based on Microsoft Windows&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;2008.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;plan to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;do&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;a double&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;encryption&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;package&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;one&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;encrypts&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CIsco,&lt;/SPAN&gt; second &lt;SPAN class="hps" title="Click for alternate translations"&gt;server&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;VPN.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;That&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;scheme is&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;you&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;gave me&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;with the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;VPN,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;supported&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CIsco,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;which&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;in&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;this scheme,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;there are pros&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Maxsim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 06:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694342#M833470</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-17T06:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694343#M833471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The eth0 of the CAS is connected to the trusted side of your network, it could be a switch for Eg.&lt;/P&gt;&lt;P&gt;It is not connected to the CAM. In VG setup the CAM and the CAS have to be in Different VLANs.&lt;/P&gt;&lt;P&gt;In REAL-IP Setup Theycould be connected in Same VLANs.&lt;/P&gt;&lt;P&gt;Router Should be the default gateway.&lt;/P&gt;&lt;P&gt;dont Enable VLAN ID passthrough.&lt;/P&gt;&lt;P&gt;InVG you will do VLAN Mapping and in Real-IP you will do routing so no nee for the pass through option.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You would like to enable management VLAN Tagging for the eth0 but not the eth1.&lt;/P&gt;&lt;P&gt;bacause you always manage the devices through eth0.&lt;/P&gt;&lt;P&gt;It just asks for the DNS server ip.&lt;/P&gt;&lt;P&gt;if you are using DNS resolution later when you setup, you would want to configure it.&lt;/P&gt;&lt;P&gt;Windows is checked well by the agent.&lt;/P&gt;&lt;P&gt;In MAC you can check the antivirus only.&lt;/P&gt;&lt;P&gt;Linux and other Mobile devices might just be authenticated and not checked for Antivirus,etc.&lt;/P&gt;&lt;P&gt;Support for Other OS is being worked by the DEVs.&lt;/P&gt;&lt;P&gt;VPN traffic can be made to pass through NAC and checked.&lt;/P&gt;&lt;P&gt;2 ways- j&lt;/P&gt;&lt;P&gt;1)just traffic passing through.&lt;/P&gt;&lt;P&gt;flow-remote user--&amp;gt;NAC--&amp;gt;internal network--&amp;gt;ASA(vpn termination point)&lt;/P&gt;&lt;P&gt;2)Termination and VPN SSO&lt;/P&gt;&lt;P&gt;flow-remote user--&amp;gt;ASA--&amp;gt;NAC--&amp;gt;internal network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Install guide:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/installation_guide/hardware/48/hi_instal.html"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/installation_guide/hardware/48/hi_instal.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;eddy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 14:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694343#M833471</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-17T14:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694344#M833473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;I do&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;not technically&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;get&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;spread&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;in&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;different&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;VLAN.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Can&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I use&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;one&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;adressnoy&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;network&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;For example&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS 172.16.0.1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM 172.16.0.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Default Gateway (router) 172.16.0.3?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 15:23:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694344#M833473</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-17T15:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694345#M833476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Max ,you need to use different subnets for assigning addresses to CAM and CAS and then assign them different vlans on the switch they connect to.you&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/1/9/47917-Setup.JPG" class="jive-image" /&gt;can use /30 subnets so that you save ip addresses.&lt;/P&gt;&lt;P&gt;I Have attached a drawing, Is this what you are planning to make.&lt;/P&gt;&lt;P&gt;I also want to know which setup mode you want to deploy your CAS in ?&lt;/P&gt;&lt;P&gt;VG or Real-ip.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;eddy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 15:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694345#M833476</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-17T15:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694346#M833477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, What is VG?&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;made ​​a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;diagram&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;of my network&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Here is&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the configuration of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Server&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Manager.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM:&lt;BR /&gt;Please enter the IP address for the interface eth0 []: 172.16.0.3&lt;BR /&gt;You entered 172.16.0.3 Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the netmask for the interface eth0 []: 255.255.255.0&lt;BR /&gt;You entered 255.255.255.0, is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the IP address for the default gateway []: 172.16.0.1&lt;BR /&gt;You entered 172.16.0.1 Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the hostname [localhost.localdomain]:&lt;BR /&gt;You entered localhost.localdomain Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the IP addresses for the name servers [172.16.0.2] :&lt;BR /&gt;You entered 172.16.0.2 Is this correct? (y/n)? [y]&lt;BR /&gt;After date and time ...&lt;BR /&gt;Enter fully qualified domain name or IP: 172.16.0.2&lt;BR /&gt;Enter organization unit name: Hotel&lt;BR /&gt;Enter organization name: Cisco&lt;BR /&gt;Enter city name: Odessa&lt;BR /&gt;Enter state code: Ukraine&lt;BR /&gt;Enter 2 letter country code: UA&lt;BR /&gt;Is this correct? (y/n)? [y]&lt;BR /&gt;New Unix password&lt;BR /&gt;Install has completed. Press &lt;ENTER&gt; to reboot.&lt;/ENTER&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS:&lt;BR /&gt;Please enter the IP address for the interface eth0 []: 172.16.0.1&lt;BR /&gt;You entered 172.16.0.1 Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the netmask for the interface eth0 []: 255.255.255.0&lt;BR /&gt;You entered 255.255.255.0, is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the IP address for the default gateway []: 172.16.0.2&lt;BR /&gt;You entered 172.16.0.2 Is this correct? (y/n)? [y]&lt;BR /&gt;[Vlan Id Passthrough] for packets from eth0 to eth1 is disabled.&lt;BR /&gt;Would you like to enable it? (y/n)? [n]&lt;BR /&gt;[Management Vlan Tagging] for egress packets of eth0 is disabled.&lt;BR /&gt;Would you like to enable it? (y/n)? [n]&lt;BR /&gt;Please enter the IP address for the untrusted interface eth1 []: 192.168.100.2&lt;BR /&gt;You entered 192.168.100.2 Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the netmask for the interface eth1 []: 255.255.255.0&lt;BR /&gt;You entered 255.255.255.0, is this correct? (y/n)? [y] &lt;BR /&gt;Please enter the IP address for the default gateway []: 192.168.100.1&lt;BR /&gt;You entered 192.168.100.1 Is this correct? (y/n)? [y]&lt;BR /&gt;[Vlan Id Passthrough] for packets from eth1 to eth0 is disabled.&lt;BR /&gt;Would you like to enable it? (y/n)? [n] &lt;BR /&gt;[Management Vlan Tagging] for egress packets of eth1 is disabled.&lt;BR /&gt;Would you like to enable it? (y/n)? [n]&lt;BR /&gt;Please enter the hostname [localhost.localdomain]:&lt;BR /&gt;You entered localhost.localdomain Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the IP address for the name server: []: 172.16.0.2&lt;BR /&gt;You entered 172.16.0.2 Is this correct? (y/n)? [y] &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Given&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;your&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;previous&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;answer&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; How &lt;SPAN class="hps" title="Click for alternate translations"&gt;better&lt;/SPAN&gt; rewrite &lt;SPAN class="hps" title="Click for alternate translations"&gt;subnet?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;These&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;two options&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;are still&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;on the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;virtual&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;machines,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;VMware.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I have&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;test&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;, including machines&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;with Windows XP,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;set the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;IP 172.16.0.2,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I can not&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;ping&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;not&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;172.168.0.1,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;not&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;172.168.0.3.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Although&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;yesterday&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;installed the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;and the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;but&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;not&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;as written&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;above&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;in the configuration,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;and I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;was able&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to enter the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;administration panel.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;But today&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;can not&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;do it&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;even goes&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;ping&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;In what&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;may&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;be the problem&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Maxsim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 19:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694346#M833477</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-17T19:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694347#M833478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all,&lt;/P&gt;&lt;P&gt;VG- Virtual gateway mode&lt;/P&gt;&lt;P&gt;It is the mode that the CAS functions in if you want it to act as a bridge or a bump in a wire. It will just map the VLANs from untrusted to the trusted side.&lt;/P&gt;&lt;P&gt;CAM and CAS cannot be in the same subnet.&lt;/P&gt;&lt;P&gt;CAM gateway as you have mentioned is &lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt; 172.16.0.1.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;which is the CASs IP....., you have to create an SVI on the switch which will be the gateway for the CAM.&lt;/P&gt;&lt;P&gt;Similarly for the CAS, an SVI on the switch will be the default gateway for the trusted eth0 of CAS.&lt;/P&gt;&lt;P&gt;Hostname is used if you have DNS configured properly, you can configure it here, but when you do High Availabilty or When you open the GUI of the CAM using we browser, use the hostname only if you have DNS configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe the new ips may have left you out of the box,&lt;/P&gt;&lt;P&gt;try doing service perfigo config again if you can go into the root access of the device,&lt;/P&gt;&lt;P&gt;or else re-image it on VMWARE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If i missed something here, kindly requote them in the next post.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;eddy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 May 2011 17:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694347#M833478</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-18T17:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694348#M833479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Firstly&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I want&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to thank you for&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;such&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;complete answers&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;hope&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;you&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;explain to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;me&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;until&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the end&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;could&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;make&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;a fully&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;working model&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;From the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;above&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;described&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;positions&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;not understand for me&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;a few things&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;1&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;If&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I do not have&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;DNS,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;then&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;how can I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;when you install&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;indicate that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;do not&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;use&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;DNS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;server?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;2&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I realized&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;that the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;need to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;specify the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;gateway&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;And&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;for the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;in&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;eth0&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;need&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to specify&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the gateway to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;himself&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;3&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;When&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I specify&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;during the installation of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS local name,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;must&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;already&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;be&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;running&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;a DNS server&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;In the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;near future&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;, I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;will install&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;as&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;you&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;suggested to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;me&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;and report the results&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I hope&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;soon to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;begin&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;setting up&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;of the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;via&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the web&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;interface&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;For&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;me,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;this&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;part of the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;setup&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;is hard&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;because&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;do not really understand&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the principle of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;setting&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN title="Click for alternate translations"&gt;Maxsim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 May 2011 19:24:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694348#M833479</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-18T19:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694349#M833480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;BR /&gt;Today I did a great job on the installation server. Attach the network diagram. I report on the steps that I did.&lt;BR /&gt;The first thing I re-install CAS and CAM.&lt;BR /&gt;Here's the new configuration.&lt;/P&gt;&lt;P&gt;I made DNS record. Zone: Hotel.&lt;BR /&gt;Install CAM:&lt;BR /&gt;Please enter the IP address for the interface eth0 []: 172.17.0.2&lt;BR /&gt;You entered 172.17.0.2 Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the netmask for the interface eth0 []: 255.255.255.0&lt;BR /&gt;You entered 255.255.255.0, is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the IP address for the default gateway []: 172.17.0.1&lt;BR /&gt;You entered 172.17.0.1 Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the hostname [localhost.localdomain]:&lt;BR /&gt;You entered localhost.localdomain Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the IP addresses for the name servers [172.18.0.2] :&lt;BR /&gt;You entered 172.18.0.2 Is this correct? (y/n)? [y]&lt;BR /&gt;After date and time ...&lt;BR /&gt;Enter fully qualified domain name or IP: 172.18.0.2&lt;BR /&gt;Enter organization unit name: Hotel&lt;BR /&gt;Enter organization name: Cisco&lt;BR /&gt;Enter city name: Odessa&lt;BR /&gt;Enter state code: Ukraine&lt;BR /&gt;Enter 2 letter country code: UA&lt;BR /&gt;Is this correct? (y/n)? [y]&lt;BR /&gt;New Unix password&lt;BR /&gt;Install has completed. Press &lt;ENTER&gt; to reboot.&lt;/ENTER&gt;&lt;/P&gt;&lt;P&gt;Install CAS:&lt;BR /&gt;Please enter the IP address for the interface eth0 []: 172.16.0.1&lt;BR /&gt;You entered 172.16.0.1 Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the netmask for the interface eth0 []: 255.255.255.0&lt;BR /&gt;You entered 255.255.255.0, is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the IP address for the default gateway []: 172.17.0.2&lt;BR /&gt;You entered 172.17.0.2 Is this correct? (y/n)? [y]&lt;BR /&gt;[Vlan Id Passthrough] for packets from eth0 to eth1 is disabled.&lt;BR /&gt;Would you like to enable it? (y/n)? [n]&lt;BR /&gt;[Management Vlan Tagging] for egress packets of eth0 is disabled.&lt;BR /&gt;Would you like to enable it? (y/n)? [n]&lt;BR /&gt;Please enter the IP address for the untrusted interface eth1 []: 192.168.100.2&lt;BR /&gt;You entered 192.168.100.2 Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the netmask for the interface eth1 []: 255.255.255.0&lt;BR /&gt;You entered 255.255.255.0, is this correct? (y/n)? [y] &lt;BR /&gt;Please enter the IP address for the default gateway []: 192.168.100.1&lt;BR /&gt;You entered 192.168.100.1 Is this correct? (y/n)? [y]&lt;BR /&gt;[Vlan Id Passthrough] for packets from eth1 to eth0 is disabled.&lt;BR /&gt;Would you like to enable it? (y/n)? [n] &lt;BR /&gt;[Management Vlan Tagging] for egress packets of eth1 is disabled.&lt;BR /&gt;Would you like to enable it? (y/n)? [n]&lt;BR /&gt;Please enter the hostname [localhost.localdomain]:&lt;BR /&gt;You entered localhost.localdomain Is this correct? (y/n)? [y]&lt;BR /&gt;Please enter the IP address for the name server: []: 172.18.0.2&lt;BR /&gt;You entered 172.18.0.2 Is this correct? (y/n)? [y] &lt;BR /&gt;After date and time ...&lt;BR /&gt;Enter fully qualified domain name or IP: 172.18.0.2&lt;BR /&gt;Enter organization unit name: Hotel&lt;BR /&gt;Enter organization name: Cisco&lt;BR /&gt;Enter city name: Odessa&lt;BR /&gt;Enter state code: Ukraine&lt;BR /&gt;Enter 2 letter country code: UA&lt;BR /&gt;Is this correct? (y/n)? [y]&lt;BR /&gt;New Unix password&lt;BR /&gt;Install has completed. Press &lt;ENTER&gt; to reboot.&lt;/ENTER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I have a problem with routing. Since the router will route to untrusted networks, I thought, what can be done on the bridge between the L3 switch CAS, CAM and VPN server. I got to emmulirovat in Packet Tracer, but I could not do it on real hardware.&lt;/P&gt;&lt;P&gt;I used command:&lt;/P&gt;&lt;P&gt;# spanning-tree portfast default&lt;/P&gt;&lt;P&gt;Then gave the IP: 107, 101, 102 VLAN&lt;/P&gt;&lt;P&gt;However, the bridge is enabled on all VLAN. Is it possible in this case to make such a route, and how?&lt;/P&gt;&lt;P&gt;This is configuration in Switch:&lt;BR /&gt;Switch#sh run&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 4936 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.1&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug uptime&lt;BR /&gt;service timestamps log uptime&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname Switch&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip subnet-zero&lt;BR /&gt;ip dhcp excluded-address 192.168.0.1&lt;BR /&gt;ip dhcp excluded-address 192.168.0.11&lt;BR /&gt;ip dhcp excluded-address 192.168.1.11&lt;BR /&gt;ip dhcp excluded-address 192.168.1.1&lt;BR /&gt;ip dhcp excluded-address 192.168.2.1&lt;BR /&gt;ip dhcp excluded-address 192.168.2.11&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool net2&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool VLAN50&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 192.168.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 192.168.0.1&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool VLAN51&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 192.168.1.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 192.168.1.1&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool VLAN52&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 192.168.2.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 192.168.2.1&lt;BR /&gt;!&lt;BR /&gt;vtp domain CoWS&lt;BR /&gt;vtp mode transparent&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;no spanning-tree vlan 100,105&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan 10,42&lt;BR /&gt;!&lt;BR /&gt;vlan 50&lt;BR /&gt; name VLAN50&lt;BR /&gt;!&lt;BR /&gt;vlan 51&lt;BR /&gt; name VLAN51&lt;BR /&gt;!&lt;BR /&gt;vlan 52&lt;BR /&gt; name VLAN52&lt;BR /&gt;!&lt;BR /&gt;vlan 53&lt;BR /&gt; name quarantine&lt;BR /&gt;!&lt;BR /&gt;vlan 100&lt;BR /&gt; name VLAN100&lt;BR /&gt;!&lt;BR /&gt;vlan 101&lt;BR /&gt; name VLAN101&lt;BR /&gt;!&lt;BR /&gt;vlan 102&lt;BR /&gt; name VLAN102&lt;BR /&gt;!&lt;BR /&gt;vlan 105&lt;BR /&gt; name vlan105&lt;BR /&gt;!&lt;BR /&gt;vlan 107&lt;BR /&gt; name vlan107&lt;BR /&gt;!&lt;BR /&gt;vlan 456&lt;BR /&gt; name healthy&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt; switchport trunk encapsulation dot1q&lt;BR /&gt; switchport trunk native vlan 99&lt;BR /&gt; switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/2&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/3&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/4&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/5&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/6&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/7&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/8&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/9&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/10&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/11&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/12&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/13&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/14&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/15&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/16&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/17&lt;BR /&gt; switchport access vlan 50&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/18&lt;BR /&gt; switchport access vlan 51&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/19&lt;BR /&gt; switchport access vlan 52&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/20&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/21&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/22&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/23&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/24&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/25&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/26&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/27&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/28&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/29&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/30&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/31&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/32&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/33&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/34&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/35&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/36&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/37&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/38&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/39&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/40&lt;BR /&gt; switchport access vlan 107&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/41&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/42&lt;BR /&gt; switchport access vlan 101&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/43&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/44&lt;BR /&gt; switchport access vlan 100&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/45&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/46&lt;BR /&gt; switchport access vlan 102&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/47&lt;BR /&gt; switchport access vlan 105&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/48&lt;BR /&gt; switchport access vlan 105&lt;BR /&gt; switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan50&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan51&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan52&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan100&lt;BR /&gt; ip address 192.168.100.111 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan101&lt;BR /&gt; ip address 172.16.0.3 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan102&lt;BR /&gt; ip address 172.18.0.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan107&lt;BR /&gt; ip address 172.17.0.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip classless&lt;BR /&gt;ip http server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt; login&lt;BR /&gt;line vty 5 15&lt;BR /&gt; login&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I then checked the ping. Ping the CAM. Since routing is not configured on the server, made a ping to CAS with the switch. Not in a straight line, not the other way ping fails. So it is necessary?&lt;BR /&gt;Waiting for your reply, because after I will add routing to the servers, I can start setting up further.&lt;BR /&gt;And one more request. Can check the gateway from CAS and CAM, whether I have?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 16:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694349#M833480</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-19T16:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694350#M833481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Max,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your initial setup on the CAS and CAM is fine.&lt;/P&gt;&lt;P&gt;From your setup as you have different setup has different subnets on both sides of the CAS(eth0 and eth1) i deduced that you are deploying your CAS in Real-IP(routed) mode.&lt;/P&gt;&lt;P&gt;As you are doing the router on a still model, it should work fine.&lt;/P&gt;&lt;P&gt;I am not 100 percent sure about the switch configuration.&lt;/P&gt;&lt;P&gt;As per your setup you are doing In-Band setup.&lt;/P&gt;&lt;P&gt;I can give you the basic configuration of the switch in that mode and you can check.&lt;/P&gt;&lt;P&gt;You can tell your email-ID and i might be able to help you on that.&lt;/P&gt;&lt;P&gt;Because looking at the whole switch from my perspective is a bit difficult.&lt;/P&gt;&lt;P&gt;You will able to look at it in the right angle.&lt;/P&gt;&lt;P&gt;I will give you a sample config and you can double check with it.&lt;/P&gt;&lt;P&gt;how does that sound?&lt;/P&gt;&lt;P&gt;I did not understand the last line of your Post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;eddy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 18:05:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694350#M833481</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-19T18:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694351#M833482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the answers are below.&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;From the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;above&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;described&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;positions&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;not understand for me&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;a few things&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;1&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;If&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I do not have&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;DNS,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;then&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;how can I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;when you install&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;indicate that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;do not&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;use&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;DNS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;server?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ans-no need to indiacte, use the ip to access the cas, for now&lt;SPAN id="result_box" lang="en"&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;2&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I realized&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;that the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;need to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;specify the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;gateway&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;And&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;for the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;in&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;eth0&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;need&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to specify&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;the gateway to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;himself&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAM?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;CAM cannot be the CAS gateway vice versa. Tehgateway for CAS on eth0 should be the next hop which will help reach the CAM and vice versa.&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;3&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;When&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I specify&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;during the installation of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS local name,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;must&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;already&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;be&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;running&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;a DNS server&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;In the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;near future&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;No nedd for DNS initially, You can give a name, it is locally significant.&lt;/P&gt;&lt;P&gt;In future DNS would be useful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 18:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694351#M833482</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-19T18:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694352#M833483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Well&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;id-email&lt;/SPAN&gt; it's mean &lt;SPAN class="hps" title="Click for alternate translations"&gt;just&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;email?&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;have&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;A class="jive-link-email-small" href="mailto:odesskia@gmail.com"&gt;odesskia@gmail.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;agree&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;it&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;is difficult&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to configure.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;What can you say&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;about the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;ping&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Should&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;ping&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;CAS?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 18:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694352#M833483</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-19T18:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694353#M833484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So if you need any other help...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 May 2011 14:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694353#M833484</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-25T14:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694354#M833485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;Well&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;set up a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;network&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;so&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;as you&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;said&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;, I understood&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;all the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;points&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;trying to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;connect&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;to the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;Web&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;site&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;I am&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;interested in&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;this question&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;what&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;is the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;latest&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;version of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;NAC?&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;What&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;'s new in&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;this version:&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;in comparison&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;with the old&lt;/SPAN&gt;&lt;SPAN title="Click for alternate translations"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 May 2011 18:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694354#M833485</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-25T18:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694355#M833486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The latest version of NAC appliance is 4.8.2.&lt;/P&gt;&lt;P&gt;The latest version of the NAC agent is nacagentsetup-win-4.8.2.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 May 2011 21:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694355#M833486</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2011-05-25T21:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: How build NAC?</title>
      <link>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694356#M833487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well. I configure CAS and CAM from link in your first answer. I think this is not full guide, because i found link in CAM, where i need add CAS. After added, server report that he look CAS, And i test to client connect to CAS. But i not have any answer from CAS, and look in log that erorr. What' i need to do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2011 07:27:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-build-nac/m-p/1694356#M833487</guid>
      <dc:creator>titans2011</dc:creator>
      <dc:date>2011-05-30T07:27:01Z</dc:date>
    </item>
  </channel>
</rss>

