Cisco NAC Appliance Network Scanner

Network Scanner allows you to scan hosts to check for known vulnerabilities. Network Scanner is integrated into the NAC Appliance Manager and NAC Appliance Server software and is not a standalone piece. Network Scanner uses Nessus to scan hosts. You add in the Nessus plug-ins of your choice. For example, you can add the plug-ins that check to see whether music file-sharing applications are running on the host. If such programs are running, you could notify the end users that they must disable or uninstall the offending software before they are allowed on the network. Network Scanner can also be used to posture assess hosts that run operating systems not supported by Clean Access Agent, such as Linux.

TIP For more information about the Nessus tool and its plug-ins, visit http://www.nessus.org or

http://www.nessus.org/plugins.

The following simple example illustrates where the pieces of a Cisco NAC Appliance design are placed in a network. Figure 3-5 shows a NAC Appliance deployment using

Layer 2 in-band. Layer 2 means that NAC Appliance Server is Layer 2 adjacent to the clients it will control. In-band means that data traffic always flows through NAC Appliance Server.

Figure 3-5 Cisco NAC Appliance Deployment Example (Layer 2 In-Band)

L2 Switch

Client PC with Clean Access Agent

NAC Appliance Server

Router or L3 Switch

Figure 3-5 Cisco NAC Appliance Deployment Example (Layer 2 In-Band)

L2 Switch

Client PC with Clean Access Agent

NAC Appliance Server i 4

Intranet

NAC Appliance Manager

Continue reading here: Cisco NAC Appliance Minimum Requirements

Was this article helpful?

0 0