Cisco NAC Appliance Solution
This topic describes how the Cisco NAC Appliance solution controls and secures networks.
|
Cisco NAC Appliance Solution |
|
|
Before allowing users onto a wired or wireless network, Cisco |
|
|
NAC Appliance: |
|
|
■ Recognizes: |
|
|
- Users, device, and role |
|
|
(guest, employee, contractor) |
RECOGNIZES |
|
■ Evaluates: |
|
|
- Identifies security policies and ENFORCES |
w |
|
vulnerabilities |
|
|
■ Enforces: |
|
|
- Enforces security policies |
EVALUATES |
|
and eliminates vulnerabilities |
|
|
© 2007 Cisco Systems, Inc. All rights reserved. |
CANAC V2.1 —1-2 |
Cisco NAC Appliance is part of the Cisco Self-Defending Network initiative to improve the ability of networks to identify, prevent, and adapt to security threats. As the central management point for your network, Cisco NAC Appliance allows you to implement security and access policies in one place instead of propagating the policies throughout the network on many different devices.
There are three essential protective functions of Cisco NAC Appliance:
■ Recognize: Recognize users, their devices, and their role in the network. This first step occurs at the point of authentication, before malicious code can cause damage.
■ Evaluate: Evaluate whether machines are compliant with security policies. Security policies can vary by user type, device type, or operating system.
■ Enforce: Enforce security policies by blocking, isolating, and repairing noncompliant machines. Cisco NAC Appliance redirects noncompliant machines to a quarantine area. Remediation then occurs at the discretion of the administrator.
1-20 Implementing Cisco NAC Appliance (CANAC) v2.1 © 2007 Cisco Systems, Inc.
Continue reading here: Cisco NAS Operating Modes
Was this article helpful?