CTA without the supplicant can be used to implement NA L2-IP or L3-IP. Uisng the NAC L2-IP solution an L2 device (switch) is configured for NAC using ARP inspection and DHCP snooping to identify new devices. Using NAC L3-IP the L3 device (router) is configured to identify using an IP Admission ACL. In either a Linux PC equipped with CTA that enters the network is identified and the network device requests posture from CTA installed on the PC.
Brian Ford | brford@cisco.com | brford@yahoo.com | 51 75 61 6c 69 74 79 20 6d 65 61 6e 73 20 64 6f 69 6e 67 20 69 74 20 72 69 67 68 74 20 77 68 65 6e 20 6e 6f 20 6f 6e 65 20 69 73 20 6c 6f 6f 6b 69 6e 67 2e | Email me when you figure this out.