CANAC

Cisco NAC Products

Cisco NAC Framework Traditional Cisco NAC Software module embedded within NAC-enabled products In-band NAC Appliance solution can be used on any switch or router Integrated framework leveraging multiple Cisco and NAC-aware vendor products Self-contained, turnkey solution Offers customers a deployment timeframe choice Adapts to customer investment protection requirements 2007 Cisco Systems, Inc. All rights Cisco NAC products come in two general categories NAC framework The NAC framework uses the...

Step 2 Configuring the Cisco NAS Interfaces Cont

Device Management > Clean Accods Servers > 10.10.10.2 Device Management > Clean Accods Servers > 10.10.10.2 Cleari cess Server Type Virtual Gateway Cleari cess Server Type Virtual Gateway Enable L2 strict mode for Clean Access Agent Trusted Interface (to protected network) IP Address Subnet Mask CD Pass through VLAN ID to managed network (Make sujrthe Clean Access Server is on VLAN n before Untrusted Interface (to managed network) IP Address Subnet Mask Default Gateway EH Pass through...

Cisco NAS Operating Modes

All rights reserved. CANAC v2.1 1-12 There are two in-band operating modes Real-IP gateway Operates as the default gateway for the untrusted network Virtual gateway Operates as a Layer 2 transparent bridge The out-of-band server types appear in the drop-down menu when you apply an out-of-band-enabled (switch management) license to a Cisco NAC Appliance deployment. There are two out-of-band operating modes Out-of-band real-IP gateway Operates as a real-IP gateway while...

Checks Rules and Requirements

Checks and rules can be either preloaded (automatically downloaded from Cisco servers) or custom-created. CHECKS assess the state of a file, application, service, or registry key. RULES contain single or multiple checks. REQUIREMENTS contain single or multiple rules. RULES contain single or multiple checks. ROLES have one or more requirements. 2007 Cisco Systems, Inc. All rights reserved.CANAC v2.1 4-12 When Cisco NAC Appliance scans a client machine, it uses requirements made up of checks and...

RealIP Gateway Configuration

Client machine IP address 192.168.12.7 Default Gateway 192.168.12.6 2007 Cisco Systems, Inc. All rights resi In the real-IP gateway configuration, the Cisco NAS operates as the default gateway for untrusted (managed) network clients. All traffic between the untrusted and trusted networks is routed through the Cisco NAS. The Cisco NAS applies the IP filtering rules, access policies, and any other traffic-handling mechanisms that you configure. When using the Cisco NAS as a real-IP gateway, you...

NAC Appliance SSO for Microsoft Windows

Cisco NAC Appliance can automatically authenticate Cisco NAA users who are already logged into a Windows domain. Cisco NAC Appliance Windows Active Directory SSO is supported only for users with Cisco NAA installed. Cisco NAC Appliance uses the cached Kerberos credentials to validate user authentication with the backend Windows Active Directory servers. Authorization is performed as a separate lookup activity in Windows Active Directory using LDAP. The Cisco NAC Appliance Windows Active...

Configuring the Network for OOB Deployment

Step 1 Connect the machines and switches and record these network settings - Administration and access VLANs - Cisco NAC Appliance interface Step 2 Configure the IP address for the switch and the administration and access VLANs. Step 3 Configure these SNMP miscellaneous settings - SNMP server administration contact information 2007 Cisco Systems, Inc. All rights reserved CANAC v2.1 3-3 For the out-of-band authentication sequence to work, you must configure your switches and routers so that...

Configuring the Cisco NAS for InBand Deployment

Step 1 Add the Cisco NAS to the Cisco NAM managed domain. Step 2 Configure the Cisco NAS interfaces. Step 3 Add managed subnets (if needed). Step 4 Configure Cisco NAS VLAN settings. 2007 Cisco Systems, Inc. All rights reserveO. CANAC v2.1 3-12 To configure the Cisco NAS for in-band deployment, follow these steps, which are described in Step 1 Add the Cisco NAS to the Cisco NAM managed domain The Cisco NAS receives its runtime parameters from the Cisco NAM and cannot operate until it is added...

Example Layer 2 InBand Central Virtual Gateway

Cisco NAS interfaces should be on a separate VLAN from manager VLAN and access VLANs. 2007 Cisco Systems, Inc. All rights re The figure shows an example Layer 2 in-band central virtual gateway Cisco NAS deployment. Consider these aspects of this configuration example VLAN for the Cisco NAM In the figure, the management VLAN for the Cisco NAM is VLAN 2. VLAN for the Cisco NAS The VLAN for the Cisco NAS must be different from the VLAN for the Cisco NAM. In the figure, the management VLAN for the...

OOB Virtual Gateway Deployment Characteristics

With an OOB deployment, there is no need for network configuration changes or DHCP scope change. During the authentication, posture assessment, and remediation process, the Cisco NAS acts as an inline Layer 2 bridge for the managed network in three ways - DHCP or DNS default is enabled via VLAN mapping for authentication to the access VLAN. - User obtains a real DHCP address from the access VLAN. - The Cisco NAS provides access to quarantine or remediation sites only. After a user successfully...

Auto Generating IP Pools and Subnets Cont

Warning messages will appear if there are errors in the configuration. Step 7 The warning messages that appear provide instructions to correct errors in the settings. When you correct all errors, a preliminary list of IP ranges appears, allowing you to review the results. Click Commit Subnet List to save the IP ranges. 2-68 Implementing Cisco NAC Appliance CANAC v2.1 2007 Cisco Systems, Inc.

The Cisco SDN Initiative

This topic describes the Cisco SDN strategy. The Cisco SDN strategy describes the Cisco vision for security systems. The foundation for a Cisco SDN is integrated security. Creating a security ecosystem includes elements of security products, technologies, and services. 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 1-5 Networks have evolved from closed systems to open, sophisticated systems. As a result, security threats have grown exponentially, both at the network perimeter and from...

Configuring a Mapping Rule

User Management > Auth Servers 'QU User Management > Auth Servers 'QU To create a mapping rule, you first add and save conditions to configure a rule expression. After a rule expression is created, you can add the mapping rule to the authentication server. Mapping rules can be cascading. If a source has more than one mapping rule, the rules are evaluated in the order in which they appear in the mapping rules list. The role for the first mapping rule that is found positive is used. After a...

Enable Vpn Sso in the Cisco NAS

Device Management gt Clean Access Servers gt 192.168.137.3 Device Management gt Clean Access Servers gt 192.168.137.3 VPN Auth Windows Auth OS Detection 2007 Cisco Systems, Inc. All rights re To enable VPN SSO in the Cisco NAS, follow these steps Step 1 Using the Cisco NAM administration console, go to Device Management gt Clean Access Servers gt IPaddress gt Authentication gt VPN Auth gt General. Step 2 Check the Single Sign-On check box to set the Cisco NAS to process the user login via...

Setting Up Guest Access Using the BuiltIn Guest Account

Image Cisco Logo v Title Cisco Cleen Access Authentication 0 Username Label 0 Login Label Default Provider 0 Password Label Q Provider Label Available Providers 0 Username Label 0 Login Label Default Provider 0 Password Label Q Provider Label Available Providers Please provide your credentials to click the Guest button for guest acc H Guest Label d Help Label Help Contents Root CA Label Install OA Cert Root CA File Clean Access CA Cert < P> To access the network please provide che i you...

Step 1 Adding the Cisco NAS to the Cisco NAM Managed Domain

Device Management > Clean Access Servers Server IP Address Server Location Server Type Device Management > Clean Access Servers Server IP Address Server Location Server Type 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 3-13 Note The Cisco NAS must be running to be added to the Cisco NAM. The first step in configuring the Cisco NAS for in-band deployment is to add an in-band Cisco NAS to the Cisco NAM managed domain. Complete these steps Step 1 From the navigation bar, choose...

Step 4 Configuring Cisco Nas Vlan Settings

The Cisco NAS acts as a VLAN termination point - VLAN identifiers are stripped from packets received at the trusted and untrusted interfaces. - This setting is the default in real-IP operating mode. The Cisco NAS performs VLAN passthrough - Packets retain their VLAN identifiers. - This setting is always used in virtual gateway operating mode. - This setting only needs to be enabled for the first of the two interfaces that receives the message. 2007 Cisco Systems, Inc. All rights reserved....

Configuring Port Profiles

You must add a port profile for each set of authentication and access VLANs that you configure on the switch. There are three types of port profiles Used for switch ports that are not connected to clients, such as printers and servers Used for switch ports that are connected to clients Port is set to the access VLAN specified in the port profile - Controlled using role settings Used for client-connected ports when role-based port mapping is configured Port is set to the VLAN ID specified in...

Checking Antivirus Product Support Information

All rights re The first task in creating either an antivirus rule or an antispyware rule is to check for the most recent and supported version of the product. Cisco NAC Appliance allows multiple versions of the Cisco NAA to be used on the network. New updates to the Cisco NAA will add support for the latest antivirus or antispyware products as they are released. Cisco NAC Appliance picks the best method to execute antivirus rule or antispyware definition checks based...

Step 3 Configure Active Directory SSO on the Cisco NAS

Device Management > Clean Access Servers > 10.10.10.4 Device Management > Clean Access Servers > 10.10.10.4 1 Status Network Filter Advanced 1 Lo in Page VPN Auth Windows Auth OS Detection i Active Directory SSO 1 NetBIOS SSO V Enable Agent-Based Windows Single Sign-On with Active Directory (Kerberos) Active Directory Server (FQDN) Active Directory Port Active Directory Domain pcount Name for CAS Account Password for CAS Active Directory SSO Auth Server V Enable Agent-Based Windows...

Cisco NAC Appliance Solution

This topic describes how the Cisco NAC Appliance solution controls and secures networks. Before allowing users onto a wired or wireless network, Cisco - Identifies security policies and ENFORCES 2007 Cisco Systems, Inc. All rights reserved. Cisco NAC Appliance is part of the Cisco Self-Defending Network initiative to improve the ability of networks to identify, prevent, and adapt to security threats. As the central management point for your network, Cisco NAC Appliance allows you to implement...

Review of Posture Assessment and Remediation

The Cisco NAC Appliance posture assessment and remediation process starts with authentication and authorization, during which the Cisco NAC Appliance enforces authorization policies and privileges. Cisco NAC Appliance authentication and authorization can support multiple user roles. During posture assessment, the Cisco NAC Appliance uses the Cisco NAA to scan a client machine for the required versions of hotfixes, antivirus software, and other software. The Cisco NAC Appliance solution supports...

Example Configuring a Kerberos Authentication Provider

All rights re You must configure the server that you want Cisco NAC Appliance to use as an authentication provider. The authentication type that you choose brings up the form appropriate to that type. To configure a Kerberos provider for Cisco NAC Appliance users, complete these steps Step 1 Choose User Management > Auth Servers > New. Step 2 From the Authentication Type drop-down menu, choose Kerberos. Step 3 In the Provider Name field, enter a name that is unique...

Configuring the SNMP Receiver SNMP Trap Settings

All rights reserved CANAC v2.1 3-19 Settings in the SNMP Receiver tab configure the SNMP receiver that is running on the Cisco NAM. The SNMP receiver receives MAC notification or linkup SNMP trap notifications from the controlled switches and sets the VLAN on the corresponding switch ports. The configuration on the switch must match the SNMP receiver settings to be able to send traps to the Cisco NAM. To configure the SNMP receiver module on the Cisco NAM, complete...

Configure a Heartbeat Timer User Inactivity Timer

Ujg Out Disconnected Users After 2o ujg Out Disconnected Users After 2o 2007Cisco Systems, Inc. All rights The heartbeat timer sets the number of minutes after which a user will be logged off the network if the user is unreachable through a connection attempt from the Cisco NAS. This feature enables the Cisco NAS to detect and disconnect users who have restarted their computers without logging out of the network. To configure a heartbeat timer for a user role, complete these steps Step 1 Choose...

Cisco NAC Appliance Agent Cisco NAA The Cisco NAA software resides on

Microsoft Windows systems and can verify if an application or service is running and if a registry key exists or if the value of a registry key is known. The Cisco NAA is referred to as a read-only agent the Cisco NAA does not alter client system information, but reads the information and reports this information to the Cisco NAC Appliance Manager (Cisco NAM). The Cisco NAA ensures that, for example, a corporate laptop has an up-to-date configuration of the standard corporate software before...

Layer 3 OOB Deployment Considerations

Layer 3 OOB is best used in routed access deployments. Layer 3 OOB can be used for remote WAN sites. Informs the Cisco NAS of the device MAC address no additional configuration needed with Cisco NAA 4.0. Web login page downloads ActiveX control or Java applet to determine device MAC address and report address back to Cisco NAS. For web login, configure the login page. 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 3-9 2007 Cisco Systems, Inc. All...

Map a VPN Gateway to an Accounting Server

Device Management > Clean Access Servers > 192.168.137.3 Device Management > Clean Access Servers > 192.168.137.3 General VPN Concentrators Accounting Servers 1 Accounting Mapping H Active Clients VPN Concentrator vpndevice 10.10.10.3 General VPN Concentrators Accounting Servers 1 Accounting Mapping H Active Clients VPN Concentrator vpndevice 10.10.10.3 Accounting Server ACS_Accounting 172.16.1.14.1646 > Accounting Server ACS_Accounting 172.16.1.14.1646 > 2007 Cisco Systems, Inc....

Creating a Custom Requirement

Network Scanner Clean Access Agent Role-Requirements Reports Updates Requirement Type Link Distribution v Do not enforce requirement Priority 10 v. File Link URL Requirement Name Manage system startup files (Optional) Description Our security policy suggests you download this Ope ratings y stem D Windows All O Windows XP Windows 2000 Requirement Type Link Distribution v Do not enforce requirement Priority 10 v. File Link URL Requirement Name Manage system startup files (Optional) Description...

Overview of Configuring the Secondary Cisco NAS

Task 1 Access the secondary Cisco NAS directly. Task 2 Configure the host information for the secondary Cisco NAS. Task 3 Configure the SSL certificate. Task 4 Configure the Cisco NAS high-availability secondary mode. Task 5 Reboot the secondary Cisco NAS. 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1 4-11 The tasks to configure the standby Cisco NAS, listed in the figure, closely parallel the tasks that are used to configure the primary Cisco NAS therefore, the first task steps that...

Making Cisco NAA Available to Users

Cisco NAM automatically publishes the Cisco NAA to each Cisco NAS on the following occasions - After every Cisco NAS installation - Each time the Cisco NAA is manually updated You can configure Cisco NAM to require Cisco NAS to install Cisco NAA on user devices. Cisco NAA supports dynamic antivirus definition checks. 2007 Cisco Systems, Inc. All rights reserved CANAC v2.1 4-5 The Cisco NAA is included as part of the Cisco NAC Appliance software. To ensure that the Cisco NAS always has the most...

Loading Nessus Plug Ins Manually

All rights reserved. CANAC v2.1 4-10 When the Cisco NAM is first installed, its Nessus scan plug-in repository is empty. You must manually load plug-ins that you have created or downloaded from the Nessus website to the Nessus scan plug-in repository in the Cisco NAM. After Nessus plug-ins are loaded, the plugins are automatically published from the Cisco NAM repository to the Cisco NASs. The Cisco NASs then perform the scan on user machines. If the Cisco NAM...

Task 2 Install Support Tools

Back J Search _ _Folders_ gH Qfilever.exe Qftonline.exe Qgetsid.exe afiaos .exe S health_chk.cmd Qhttpcfg.exe I3 iadstools.dll 9 iadstools.doc 9 iasparse.doc asparse .exe inetorgpersonfix.doc inetorgpersonf ix. Idf Ti ioloasum.cmd ksetup.exe Jlldp.doc Hldp.exe jyiowiosrv.dll Qlowiosrv.tlb 14 KB 26 KB 6 KB 34 KB 9 KB 16KB 825 KB 167 KB 39 KB 37 KB 21 KB 1 KB 11 KB 23 KB 88 KB 13,703 KB 257 KB 8KB 3 KB Application Application Application Application Windows Command , Application Application...