Appliance Server

How Vpn Sso Works

VPN SSO operates using a trust model. NAC Appliance trusts the VPN device to correctly perform user authentication for the client VPN tunnels. After this authentication is complete, the VPN device sends a RADIUS message to NAC Appliance with the necessary details of who just successfully authenticated. Given that NAC Appliance trusts the VPN device's messages, the VPN client is allowed to bypass NAC authentication and proceed directly to posture assessment or certification. Figure 5-8 shows how...

Global Versus Local Settings

Fixed Asset Upload

The concept of global versus local settings can help with quick and efficient NAC deployments. Most parameters are configured globally and automatically applied to all NAS servers. Global settings include fields that apply to all added NAS servers. Figure 7-15 shows the global settings in the NAM GUI. Figure 7-15 Global Settings for All NAS Servers Figure 7-15 Global Settings for All NAS Servers The global parameters are as follows Device Management > Filters This is where you set login and...

Outof Band Mode

Out-of-Band mode was created to fill some of the perceived gaps of In-Band mode operating in a LAN environment. OOB is designed for one purpose to control hosts that connect directly to Cisco LAN switches. It is not capable of operating in wireless or VPN environments or those with non-Cisco switches. Businesses wanted true switch port-level network admission control, and they did not want the appliance to be a bottleneck on their high speed LANs. To accomplish this, OOB uses switch port-level...

Login Steps for OOB in L3 Adjacency Real IP Mode

Oob Cisco Switches

These certification steps are based on the perspective of the host and user in Figure 4-15. The traffic control method used is policy-based routing. The host has Clean Access Agent installed and is multiple Layer 3 hops from NAC Appliance Server. NAC Appliance Server is in Real IP Gateway mode and routing between the untrusted and trusted networks. NAC Appliance is not configured for network scanning, only Clean Access Agent posture assessment. The Cisco LAN switch is configured to send both...

Switches Supported by NAC Appliance Outof Band

This section details the Cisco switch models and the required minimum software version you must have in your environment if you plan to use NAC Appliance in Out-of-Band mode. This information is constantly being updated, so be sure to check the latest NAC Appliance Release Notes on http www.cisco.com. Table 4-3 lists the supported switches as of this writing. Table 4-3 Supported Switches for Cisco NAC Appliance Out-of-Band Table 4-3 Supported Switches for Cisco NAC Appliance Out-of-Band Minimum...

Defining the Security Domains

A security domain is used to group network areas, host types, and locations under a common host security policy. The goal of creating security domains for a NAC Appliance solution is to define which networks and locations will require hosts to use the NAC Appliance solution and which locations will not. It is also necessary to define the devices that will require exemption from the NAC Appliance solution within a given security domain. Figure 6-2 shows an example of security domains. Most...

Layer 3 Outof Band Traffic Control Methods

Another important design requirement of using Layer 3 Out-of-Band is traffic control. While in the authentication VLAN, no client traffic should be allowed to roam freely throughout the network It must be controlled. Because NAC Appliance Server is not Layer 2 adjacent to the client, the client's traffic is not forced through NAC Appliance Server. If you do not implement controls on the authentication VLAN traffic, it can route to anywhere the local default router allows it to go. Of course,...

How to Connect NAM

There are two methods available to connect the NAM initially. Both methods will access the CLI required to perform the initial configuration. Option 1 is the preferred method, but both are listed. Connect a keyboard and monitor to the back of the NAM appliance. A mouse is not required. Connect a serial cable from a laptop or desktop PC to the serial port (typically DB9 connector) on the NAM appliance. Open a terminal emulation program, such as HyperTerminal or SecureCRT, on the laptop or...

LDAP Browser Not Required but Very Helpful

Before configuring an LDAP lookup server in NAM, having a good understanding of Active Directory and LDAP tree structure is helpful. To assist with this learning, an LDAP directory browser is highly recommended. For this exercise, a free LDAP browser from Softerra (http www.softerra.com ) is used to help walk through the LDAP tree and correctly identify user attributes. Softerra is probably not the only free LDAP browser available on the Internet. You can use any other tool you choose to...

User Attributes in Active Directory

Active Directory tree structure can be multilevel and quite complex. Therefore, it is important that the NAC Appliance administrator work with the AD server administrators to coordinate the user-role-to-AD-attribute mapping effort. The scope of this book is not to discuss how to correctly configure and deploy AD in an enterprise environment. Therefore, the test lab used in this exercise is simplified to demonstrate the technique of how to map AD user attributes to NAC mapping rules. Earlier,...

Understanding and Defining NAC Appliance User Roles

The effective use of user roles is a key component to any successful NAC Appliance deployment. NAC Appliance is role based a user role defines the host security policies that will be required for its members. The concept of user roles is the backbone of NAC Appliance. User roles are analogous to groups in Active Directory (AD). Like groups, users are assigned membership to a specific user role. Unlike groups, however, users can be a member of only one user role at a time. NAC Appliance moves...

Nam Gui Description

After the initial licensing, all NAM configurations are performed via a secured web browser session at https NAM_IP. Figure 7-3 shows the initial NAM login screen. After you enter the NAM GUI, you can change the admin account and password under the Administration > Admin Users page. After logging in, the main NAM configuration screen is displayed, as shown in Figure 7-4. Figure 7-4 Main NAM Configuration Screen Cisco Clean Access Manager - Microsoft Internet Explorer AridrH55 dj Currant...

Deployment Plan Overview

The deployment plan is broken up into three main phases. Each phase has several sections. A sample deployment plan outline follows. 1.1 Determine Goal of the Proof of Concept 1.2 Determine Scope of the Proof of Concept 1.3 Determine Criteria for Success 1.4 Work Assignments 1.5 Document Test Plan and Results 1.6 Post-Deployment Review 2 Pilot Phase 2.1 Determine Goal of the Pilot Phase 2.2 Determine Scope of the Pilot Phase 2.3 Determine Criteria for Success 2.4 Work Assignments 2.5 Document...

Clean Access Agent and Web Login with Network Scanner

This section will deal with how to best use the web login with Network Scanner and Clean Access Agent in your Cisco NAC Appliance design. Understanding where and when to use Clean Access Agent or web login is critical to producing a successful design. For this discussion, it should always be assumed that web login will include the Network Scanner function. The Network Admission Control Appliance solution has three main functions authentication, posture assessment, and remediation. Each of these...

Sample Agent Installation

Now you will examine the user-side experience relating to installing Cisco Clean Access Agent. Step 1 The user attempts to access a website via a web browser. Any other application connection attempt will result in a failed connection until web authentication occurs because the system has not yet been granted access. Step 2 The web browser displays a message, shown in Figure 9-10, that the user is about to be redirected to the network authentication page. Figure 9-10 Redirection to the Web...

The Weakest Link Internal Network Security

The rapid spread of e-commerce, e-learning, and e-business coupled with the growing reliance on information technology (IT) as a business enabler brings new information security challenges to organizations, including the following Increased vulnerability-based attacks, which can cause large-scale business disruptions and directly result in productivity loss. Diminished security boundaries resulting in an increase in unauthorized access and internal attacks. The lack of an established security...

Configuring the AD Server and Running the ktpass Command

The following is how to prepare and configure the AD server for AD SSO Step 1 Create the NAS user account in AD. Step 2 Install the support tools from the Windows 2003 Server CD. Step 3 Run the ktpass.exe command. Use the following steps to create the NAS user account in the AD server Step 1 In the AD server, go to Start > Administrative Tools > Active Directory Users and Computers. Step 2 Go to the Users folder under the AD domain. In this example, the AD domain is selab.net. Step 3...

Cisco Content Switching Module or Standalone Content Services Switch

The following are the prerequisites for Cisco Content Switching Module or standalone Content Services Switch Must have either two CSS or one CSM Appliance. NAC Appliance servers must be in Real-IP Gateway mode. The CSM and CSS are advanced Layer 4-to-Layer 7 load-balancing appliances. Using CSM or CSS load balancing allows you to scale NAC Appliance protection by distributing traffic across multiple NAC Appliance Servers on a per-client basis. The CSS and CSM are capable of providing both...

NAC Licensing

After setting up NAM and accessing the GUI (https NAM_IP) for the first time, you will be prompted to enter a valid product license. Without it, you cannot proceed with further NAC configurations. See Figure 7-1 for initial license installation. Figure 7-1 NAC Manager Licensing Page The product license for this Installation (MAC Address 0Q 30 48 80 43 D6) Is either Invalid, expired, or not yet set. Please choose the correct license that you will need Product Evaluation If you are evaluating the...

Configuring Traffic Policies and Ports in the Unauthenticated Role for AD Authentication

By default, NAS permits only DNS and DHCP traffic in the Unauthenticated role. For AD users to authenticate via Kerberos to the AD domain, ports must be opened on NAS to allow the authentication process to pass through in the Unauthenticated role. This will also allow GPO and scripts to run after the user authentication. The required TCP and User Datagram Protocol (UDP) ports are listed next. TCP 135 (remote-procedure call RPC ) TCP 389 (LDAP) or TCP 535 (LDAP with Secure Sockets Layer SSL )...

Enabling GPO Updates

Starting with NAC software 4.1.0, NAC Agent (4.1.0) can retrigger a GPO update after an AD user has signed in to the network. This is helpful in ensuring that all AD domain users inherit the appropriate user policies as defined by the AD administrator. For example, the administrator can create a policy that prevents the users from changing their desktop wallpaper. With the 4.1.0 release, NAC Agent executes the gpupdate command to retrigger the Group Policy update after login and prevent users...

NAC as an Appliance

Cisco NAC Appliance (formerly known as Cisco Clean Access) comes from the Cisco 2004 acquisition of Perfigo. NAC Appliance was designed as a self-contained NAC solution, able to authenticate, posture assess, quarantine, and remediate without the need to tie in multiple products from various certified vendors. Due to its rapid and flexible deployment capabilities, NAC Appliance has attained a 45 percent market share, according to a November 2006 Frost & Sullivan report. See Figure 2-1 for the...

Sample HSP Format for Documenting NAC Appliance Requirements

As discussed, the NAC Appliance uses several mechanisms to define what it should look for, or posture assess, on a given host. It also has several mechanisms for the proper remediation of any failed security requirements. Ultimately, the host security requirements and remediation steps that are performed on a client are based on the user role of the client. With this in mind, your HSP should have sections for each user role. Under each user role section, you would have the checks, rules, and...

Agent Login

The Agent Login page of the General Setup tab provides the ability to configure how users authenticating via the CCA Agent will be processed and what options they will have and be able to see on this page. Figure 9-4 shows the configuration options. The following explains the options on this page User Role Select the appropriate user role from the drop-down selection tool to choose what role to apply. Operating System Select the operating system from the drop-down to ensure that only users with...

Discovered Clients Page

The Discovered Clients page displays all the clients discovered from SNMP MAC-notification or linkup and linkdown traps sent from controlled switch ports. It serves as a location database, letting NAC Appliance Manager know which switch port a particular client (MAC address) is plugged into. The Manager uses this list when it needs to set a VLAN (authentication or access VLAN) for an out-of-band client. When a client first connects to a switch port, the switch sends an SNMP MAC-notification or...

Cisco NAC Appliance Network Scanner

Network Scanner allows you to scan hosts to check for known vulnerabilities. Network Scanner is integrated into the NAC Appliance Manager and NAC Appliance Server software and is not a standalone piece. Network Scanner uses Nessus to scan hosts. You add in the Nessus plug-ins of your choice. For example, you can add the plug-ins that check to see whether music file-sharing applications are running on the host. If such programs are running, you could notify the end users that they must disable...

Step 8 Configuring a Switch Group

A preconfigured Default group is already present. When you add switches to be managed by the NAC Appliance Manager, they are added to the Default group. You can configure additional groups and then add the switches in a particular group. By doing this, when you list the switches, you can list them by group. This step is useful if you have a large number of switches to be managed by NAC Appliance. In this example, you will configure a group called cat3750, as shown in...

Cisco Clean Access Agent

Technically, Clean Access Agent and Network Scanner are optional components. However, in most cases, you will use the Clean Access Agent and Network Scanner in your deployment. CAUTION If you choose not to use either the Clean Access Agent or the Network Scanner, then you cannot perform any host security assessment checks (for example, checking for up-to-date antivirus definitions). You will, however, be able to perform user authentication checking via web login. Clean Access Agent is a free...

Cisco NAC Appliance Minimum Requirements

Cisco NAC Appliance Manager and NAC Appliance Server can be purchased two ways. You can buy only the software from Cisco and buy the hardware somewhere else, or you can buy the hardware and the software together in one of several appliance models available from Cisco. Typically, the term appliance means that the hardware and software come as a unit and you don't have the flexibility to buy your own hardware. That is not the case with NAC Appliance. The NAC Appliance software-only option is...