06-07-2010 04:08 AM - edited 02-21-2020 03:58 AM
Hello,
Just want to clear how can I configure the NAC to direct the user to the untrusted interface of CAS automatically.
Now, I am manually entering the ip of the untrusted interface to my internet explorer before I can have NAC agent to download.
How can I direct the internet explorer to the untrusted interface of the CAS without manually entering the ip address of the CAS untrusted interface?
thank you and best regards.
06-07-2010 06:29 AM
Hi,
In a properly designed NAC setup, this should happen automatically. For example if your setup is L2 (the CAS can see the ARP traffic from your clients) then when you browse to any site, the traffic should hit the untrusted interface of the CAS and that should prompt a redirection page. If it's L3 and multiple hops away, then you have to use either PBRs to force the traffic to the untrusted interface of the CAS or use ACLs in certain scenarios.
If you're able to get to the network or internet from your untrusted subnets without the CAS prompting you, then there is another route for the traffic to take and you will have to troubleshoot from that angle.
HTH,
Faisal
06-08-2010 07:49 AM
IC. Thanks. So If I have 4 routers to reach the untrusted interface of CAS should I configure the 4 routers of PBR.?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide