<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 9800 - NAC State feature in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865327#M257670</link>
    <description>&lt;P&gt;Thank you. &amp;nbsp;I guess I was a little confused since this article that deals with iPSK doesn't have to enabled:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216130-configure-catalyst-9800-wlc-ipsk-with-ci.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216130-configure-catalyst-9800-wlc-ipsk-with-ci.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2023 17:38:33 GMT</pubDate>
    <dc:creator>tiluna</dc:creator>
    <dc:date>2023-06-30T17:38:33Z</dc:date>
    <item>
      <title>WLC 9800 - NAC State feature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865289#M257667</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to figure out on what WLAN's I would use this feature on. &amp;nbsp;Is this specifically for CWA?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 16:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865289#M257667</guid>
      <dc:creator>tiluna</dc:creator>
      <dc:date>2023-06-30T16:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 - NAC State feature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865312#M257668</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- If you are referring to &lt;STRONG&gt;Network Access Control&lt;/STRONG&gt; ; let's say to start with it is a common feature usually used on all your WLAN's ; have a look at this document :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-and-catalyst-9800-series-integration-guide/ta-p/3753060" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-and-catalyst-9800-series-integration-guide/ta-p/3753060&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 16:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865312#M257668</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-06-30T16:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 - NAC State feature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865314#M257669</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;NAC State is not only for CWA, it is also used for 802.1x.&amp;nbsp; The concepct of NAC state come from the past. You can see that on the WLC for AirOS you have three option about NAC State:&lt;/P&gt;
&lt;P&gt;NAC ISE , SNMP NAC and None.&lt;/P&gt;
&lt;P&gt;You can choose NAC ISE&amp;nbsp; for use ISE Server as NAC and you can choose SNMP NAC for NAC out-of-the band.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you were to deploy Wireless out-of-band you need to choose SNMP NAC but I never saw this kind of deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="pTC_TableCap"&gt;Table 4-1 &lt;A target="_blank" name="79494"&gt;&lt;/A&gt;Wireless In-Band vs. Out-of-Band Deployment&lt;/P&gt;
&lt;TABLE style="border: 1px solid #dddddd; width: 100%;" border="1" width="96%" cellspacing="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TH style="border: 1px solid #dddddd; width: auto;" scope="col"&gt;
&lt;DIV class="pCH1_CellHead1"&gt;&lt;A target="_blank" name="pgfId-1056918"&gt;&lt;/A&gt;Wireless In-Band Deployment Characteristics&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH style="border: 1px solid #dddddd; width: auto;" scope="col"&gt;
&lt;DIV class="pCH1_CellHead1"&gt;&lt;A target="_blank" name="pgfId-1056920"&gt;&lt;/A&gt;Wireless Out-of-Band Deployment Characteristics&lt;/DIV&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD style="border: 1px solid #dddddd; width: auto; overflow-wrap: break-word;"&gt;
&lt;P class="pB1_Body1"&gt;&lt;A target="_blank" name="pgfId-1056922"&gt;&lt;/A&gt;The Clean Access Server (CAS) is always inline with user traffic (both before and following authentication, posture assessment and remediation). Enforcement is achieved through being inline with traffic.&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border: 1px solid #dddddd; width: auto; overflow-wrap: break-word;"&gt;
&lt;P class="pB1_Body1"&gt;&lt;A target="_blank" name="pgfId-1056924"&gt;&lt;/A&gt;The Clean Access Server (CAS) is inline with user traffic only during the process of authentication, assessment and remediation. Following that, user traffic does not come to the CAS. Enforcement is achieved through the use of SNMP to coordinate with Wireless LAN Controllers (WLCs) and to assign/reassign VLAN assignments.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD style="border: 1px solid #dddddd; width: auto; overflow-wrap: break-word;"&gt;
&lt;P class="pB1_Body1"&gt;&lt;A target="_blank" name="pgfId-1056926"&gt;&lt;/A&gt;The CAS can be used to securely control authenticated and unauthenticated user traffic.&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border: 1px solid #dddddd; width: auto; overflow-wrap: break-word;"&gt;
&lt;P class="pB1_Body1"&gt;&lt;A target="_blank" name="pgfId-1056928"&gt;&lt;/A&gt;The CAS can control user traffic during the authentication, assessment and remediation phase, but cannot do so post-remediation since the traffic is Out-of-Band.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD style="border: 1px solid #dddddd; width: auto; overflow-wrap: break-word;"&gt;
&lt;P class="pB1_Body1"&gt;&lt;A target="_blank" name="pgfId-1277396"&gt;&lt;/A&gt;Bandwidth restricted to maximum allowable throughput for installed Clean Access Server(s).&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border: 1px solid #dddddd; width: auto; overflow-wrap: break-word;"&gt;
&lt;P class="pB1_Body1"&gt;&lt;A target="_blank" name="pgfId-1277398"&gt;&lt;/A&gt;Out-of-Band bandwidth not restricted by Clean Access Servers in network, as all client traffic bypasses CASs once clients are authenticated.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 30 Jun 2023 16:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865314#M257669</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-06-30T16:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 - NAC State feature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865327#M257670</link>
      <description>&lt;P&gt;Thank you. &amp;nbsp;I guess I was a little confused since this article that deals with iPSK doesn't have to enabled:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216130-configure-catalyst-9800-wlc-ipsk-with-ci.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216130-configure-catalyst-9800-wlc-ipsk-with-ci.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 17:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865327#M257670</guid>
      <dc:creator>tiluna</dc:creator>
      <dc:date>2023-06-30T17:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 - NAC State feature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865340#M257671</link>
      <description>&lt;P&gt;Got it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I have no experience with iPSK&amp;nbsp; but for standard 802.1x authentication, it is requested the NAC State is checked. But there was some change for 9800. We can see that the alternatives now is NAC type RADIUS and XWF.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FlavioMiranda_0-1688147272237.png" style="width: 712px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189073i07E95C35208E5E07/image-dimensions/712x372?v=v2" width="712" height="372" role="button" title="FlavioMiranda_0-1688147272237.png" alt="FlavioMiranda_0-1688147272237.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 17:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4865340#M257671</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-06-30T17:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 - NAC State feature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4870185#M257925</link>
      <description>&lt;P&gt;NAC is also just used to enable CoA (Change of Authorization) in conjunction with "aaa server radius dynamic-author"&amp;nbsp;&lt;SPAN&gt;as in&amp;nbsp;&lt;/SPAN&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2023 15:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-nac-state-feature/m-p/4870185#M257925</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-07-08T15:22:23Z</dc:date>
    </item>
  </channel>
</rss>

