InBand Process Flow Cont

Laptop is assessed and quarantined and remediation begins.

Role = Quarantine i

Cisco NAA

Auth Server IP: 10.1.1.25

Cisco NAS

Cisco NAS

DNS and DHCP Server DNS and DHCP Server

Next steps

© 2007 Cisco Systems, Inc. All rights reserved.

6. The Cisco NAA that is running on the user laptop performs a posture assessment. That is, the Cisco NAA collects data about the laptop operating system, software, and hardware vulnerabilities. The Cisco NAA then sends a posture report to the Cisco NAS to make a network admission decision about the user device.

7. The Cisco NAS forwards the posture report to the Cisco NAM for further analysis. If the Cisco NAM determines that the laptop is not in compliance with security and vulnerability standards, it instructs the Cisco NAS to put the laptop into the temporary role. The temporary role can be as small as a /30 subnet.

8. The Cisco NAM sends the necessary remediation steps to the Cisco NAA that is running on the user laptop and starts the session timer for the user session.

© 2007 Cisco Systems, Inc. Cisco NAC Appliance Implementation 3-5

Was this article helpful?

0 0

Post a comment