Network Admission Control NAC in Wireless Networks

Network Admission Control (NAC) was initially designed as two separate solutions: the NAC Framework and NAC Appliance (formerly known as Cisco Clean Access). The most commonly deployed NAC solution for wireless networks is the NAC Appliance. This section covers how to integrate the Cisco NAC Appliance into the Cisco Unified Wireless solution.

As mentioned in previous chapters, the NAC Appliance has three major components:

• Clean Access Server (CAS)

• Clean Access Manager (CAM)

Clean Access Agent

In the example illustrated in Figure 8-26, the CAS is configured inline and managed by the CAM (172.18.85.181). All wireless traffic will pass through the server before it can reach the corporate network or the Internet. The goal in this example is to separate guest users from employees. The guest users will have only limited access to the Internet via HTTP and HTTPs. The employees will have access to the corporate resources.

Two SSIDs are configured in the Figure 8-26 example:

• GUESTNET: Used by guests

• CORPACCESS: Used by employees

The WLC is configured to broadcast the GUESTNET SSID, but not the CORPACCESS.

TIP As a best practice, it is recommended that you use different SSIDs for your employees and guest wireless users. For your employees (internal users), you can also use 802.1X authentication and strong encryption (WPA with TKIP/MIC or WPA2 with AES).

The following sections provide the step-by-step procedures for configuring the NAC Appliance (CAM and CAS), the WLC, and the NAC Agent configuration.

Figure 8-26 Cisco NAC Appliance Integration to Cisco Unified Wireless Solution

□□□□L □□□□L □□□□L

Corporate Network

Guest Clients

Employees

AP-1

Trusted Un-trusted

192.168.40.2

Guest Clients

Employees

AP-1

Trusted Un-trusted

AP-2

172.18.85.181

172.18.85.9

172.18.85.181

Continue reading here: Protecting Cisco Unified Communications Manager Express CME

Was this article helpful?

0 0