Cisco NAC Appliance Network Scanner
Network Scanner allows you to scan hosts to check for known vulnerabilities. Network Scanner is integrated into the NAC Appliance Manager and NAC Appliance Server software and is not a standalone piece. Network Scanner uses Nessus to scan hosts. You add in the Nessus plug-ins of your choice. For example, you can add the plug-ins that check to see whether music file-sharing applications are running on the host. If such programs are running, you could notify the end users that they must disable or uninstall the offending software before they are allowed on the network. Network Scanner can also be used to posture assess hosts that run operating systems not supported by Clean Access Agent, such as Linux.
TIP For more information about the Nessus tool and its plug-ins, visit http://www.nessus.org or
http://www.nessus.org/plugins.
The following simple example illustrates where the pieces of a Cisco NAC Appliance design are placed in a network. Figure 3-5 shows a NAC Appliance deployment using
Layer 2 in-band. Layer 2 means that NAC Appliance Server is Layer 2 adjacent to the clients it will control. In-band means that data traffic always flows through NAC Appliance Server.
Figure 3-5 Cisco NAC Appliance Deployment Example (Layer 2 In-Band)
L2 Switch
Client PC with Clean Access Agent
NAC Appliance Server
Router or L3 Switch
Figure 3-5 Cisco NAC Appliance Deployment Example (Layer 2 In-Band)
L2 Switch
Client PC with Clean Access Agent
NAC Appliance Server i 4
Intranet
NAC Appliance Manager
Continue reading here: Cisco NAC Appliance Minimum Requirements
Was this article helpful?