Network Admission Control

VPN Configuration on the Cisco VPN Client

The Cisco VPN Client, also known as the Cisco Easy VPN Client, initiates an IPSec tunnel to the VPN 3000 concentrator. If the configuration and user credentials are valid, the tunnel is established and traffic is processed over it. The Cisco VPN clients come in two different flavors However, the Cisco NAC implementation is currently supported only on the software-based VPN clients. The software-based VPN client runs on a variety of operating systems, such as Windows, Solaris, Linux, and MAC OS...

Configuring the Agentless Host Policy on ACS

The steps required to configure the Agentless Host Policy for NAC-L3-IP, NAC-L2-IP, and NAC-L2-802.1X are almost identical. The only difference is the NAC template used to create the policy and the method of enforcement through the authorization policy. Follow these steps to create a NAC Agentless Host Policy using ACS's built-in templates Step 1 From the navigation frame on the left, select Network Access Profiles. Step 2 The Network Access Profiles page appears. Click the Add Template Profile...

Installation of Qualys Guard Scanner Appliance

The QualysGuard Scanner Appliance is a hardware-based appliance that provides an out-of-the-box integration for the NAC Framework. When you are ready to install the Scanner Appliance into your network, consider the following things first IP address to be assigned to the LAN interface IP address to be assigned to the WAN interface Even though you can assign a DHCP address on the LAN and WAN interfaces, it is highly recommended that you configure static IP addresses on the interfaces. The...

Network Admission Control

Reports of data and identity theft have become hot topics in the news recently. Unfortunately, they have also become fairly common, often resulting in millions of dollars' worth of damage to the companies affected. Traditionally, network security professionals have focused much of their time securing the front door to their networked companies their Internet presence. Stateful firewalls often sit at the gateways, and, in most cases, these are supplemented with inline intrusion-prevention...

Cisco Secure Access Control Server

The Cisco Secure Access Control Server, hereafter referred to as ACS, is the central core component in the NAC Framework. Whereas switches, routers, concentrators, and access points are the brawns of NAC (limiting access and enforcing policy), ACS is the brains. It is responsible for receiving the posture credentials from the end hosts and validating them against the policies defined by the administrator. It then sends the authorization policy to the enforcement device where it is applied....

Configuring NACL2IP

This section guides you on how to configure NAC-L2-IP on Cisco Catalyst switches running Cisco IOS and CatOS. Figure 4-2 illustrates the topology used in the following examples. Figure 4-2 Configuring NAC-L2-IP Example Network VLAN110 The following steps are necessary to configure NAC-L2-IP on a Cisco Catalyst running Step 1 Enable Authentication, Authorization, and Accounting (AAA) services 6503-A(config) aaa new-model Step 2 Enable EAPoUDP RADIUS authentication 6503-A(config) aaa...

Windows Wireless Zero Configuration

The Cisco Secure Services Client disables the Windows Wireless Zero Configuration (WZC) utility automatically when it binds to the network interfaces. Disabling the Cisco Secure Services Client by right-clicking the system tray status icon and deselecting Active restores the WZC on the interfaces previously controlled by the Cisco Secure Services Client. NOTE You can define several network policies in the client to allow end users to connect to various open wireless networks. However, you must...

Cisco Wireless Devices

NAC Framework support for wireless devices is available on autonomous Access Points (AP), lightweight access points running the Lightweight Access Point Protocol (LWAPP), and the Wireless LAN Services Module (WLSM) for the Catalyst 6500. Table 1-4 lists the wireless devices and minimum supported software. Table 1-4 NAC Support in Wireless Devices Table 1-4 NAC Support in Wireless Devices Aironet 1100, 1130AG, 1200, 1230AG, 1240AG, 1300 IOS-based access points Cisco IOS Release 12.3(7)JA or...

Cisco Software Clients

The Cisco VPN client uses aggressive mode if preshared keys are used and uses main mode when public key infrastructure (PKI) is used during Phase 1 of the tunnel negotiations. After bringing up the Internet Security Association and Key Management Protocol Security Association (ISAKMP SA) for secure communication, the Cisco VPN 3000 concentrator prompts the user to specify the user credentials. In this phase, also known as X-Auth or extended authentication, the VPN 3000 concentrator validates...

NAC Report Agentless Clientless Hosts

Another very useful piece of information to know during the rollout of NAC is the number of agentless (clientless) hosts in your network. These hosts represent users who have not installed the CTA agent. Before implementing any restrictive policy, you will want the number of agentless hosts to less than 10 percent. You can keep a close eye on this number by running the agentless hosts report with a small customization, as follows Step 1 Log in to the CS-MARS GUI and click the Query Reports tab...

Small Business Network Topology

The typical topology in a small business consists of one or more switches connected to a router, which, in turn, connects to the Internet. A dedicated firewall also might function between the Internet-facing router and the switches, or the router might have firewalling capabilities (one example is Cisco IOS Firewall running on a Cisco router). In this chapter, we use the topology shown in Figure 13-1 to represent the topology of a standard small business. The business is connected to the...

Configuration of Qualys Guard Scanner Appliance

Implementation Posture Control

After setting up the Scanner Appliance, you can access it through the Qualys website, at http qualysguard.qualys.com. The web page prompts you to specify a username and a password. When your authentication credentials are successful, the Qualys website shows all the options to manage your Scanner Appliance. Browse to Preferences > Account and click the Edit icon for your Scanner Appliance. A new browser window pops up showing the Scanner Appliance Information. Make sure that Enable NAC is...

Installing the pnlog Agent on ACS

ACS currently does not have a mechanism to forward events to CS-MARS. Instead, CS-MARS receives events from ACS through the pnlog agent. The pnlog agent is an application that you install on the ACS machine or, if using an ACS Appliance, install the pnlog agent on the same machine as the Remote Agent. The pnlog agent monitors the log files ACS (or the Remote Agent) writes to disk, and then forwards events in the log files as syslog messages to CS-MARS. CS-MARS receives these syslog messages and...

Defining ACS as a Reporting Device within CSMARS

Before CS-MARS will analyze the events received from ACS, you must define ACS as a monitored device within CS-MARS. Follow these steps to accomplish this task Step 1 Log in to the CS-MARS GUI interface and select the Admin tab. Step 2 In the Device Configuration and Discovery Information section, click the Security and Monitor Devices link. Step 3 Click the Add box on the far right of the screen. Step 4 In the Device Type drop-down list, select Add SW Security Apps on New Host. Step 5 Under the...

Creating Network Access Profiles Using NAC Templates

The NAC configuration on ACS really consists of the following four policies Protocols, Authentication, Posture Validation, and Authorization. Each of these policies can also contain multiple components. The protocols policy separates the authentication requests based on protocol EAP-FAST for NAC-L2-802.1X, and PEAP for NAC-L2-IP and NAC-L3-IP. The authentication policy defines what databases are used for authentication, and it also is used to set up the agentless host configuration. The...

Installing ACS on a Windows Server

Installing ACS on Windows is simple and straightforward. Like most Windows applications, ACS uses the Microsoft InstallShield installer. Therefore, you should be familiar with the process. To install ACS, complete these steps NOTE Installing ACS over Terminal Services (or Remote Desktop) is not supported. However, you can use VNC (Virtual Network Computing's remote desktop utility) to install ACS remotely. Step 1 Log in to the server using a local Administrator account. Step 2 Insert the ACS CD...

MAC Authentication Bypass

MAC authentication bypass or MAC Auth Bypass is an 802.1X feature to control policies for NAC agentless hosts. MAC authentication bypass is configured on a per-port basis and currently is supported only on the Catalyst 6500 running CatOS. When this feature is enabled, the switch makes a RADIUS request to the Cisco Secure ACS server with the MAC address of the client machine that is attempting to connect to the network. If Cisco Secure ACS finds the MAC address of the client machine in its...

Antivirus Policy Servers and the Host Credential Authorization Protocol HCAP

Cisco Systems developed the Host Credential Authorization Protocol (HCAP) to provide the communication channel between Cisco Secure Access Control Server (ACS) and third-party posture-validation servers, such as antivirus software. HCAP uses Secure Socket Layer (SSL) as the communication medium to exchange EAP-based credentials between Cisco Secure ACS and the posture-validation servers. ACS forwards client credentials to one or more antivirus vendor servers and receives posture token response...

Cisco Secure ACS Database Replication

Network Admission Control

This section covers how to configure database replication on Cisco Secure ACS. Database replication enables an administrator to duplicate parts of the primary Cisco Secure ACS configuration to one or more secondary Cisco Secure ACS servers. In this case, you can configure the NAC network access devices (NADs) to use these secondary Cisco Secure ACS servers if the primary server is not reachable. When you configure database replication, you can select the specific functionality of the primary...

Configuration of Csacs Server

Follow these steps to configure the CS-ACS server Step 1 Load the ADF. Step 2 Define the QualysGuard Scanner Appliance. Step 3 Set up network access profiles for the audit server. Step 4 Configure shared profiles. Step 5 Set up authorization policy for network access profiles. Step 6 (Optional) Install QualysGuard Root CA into CS-ACS. The following sections cover these steps. Before you configure the audit server on CS-ACS, you need to import the attribute definition file (ADF) for the...

Medium Size Enterprise NAC Solution Highlights

Before a solution is deployed in the production environment, SecureMe wants to document all the major highlights of the solution. This is necessary in case new network or security requirements come up later and they need to expand this solution to meet those requirements. The major highlights of the solution include the following The NAC Framework solution will install the CTA agent on all the host machines owned by SecureMe. SecureMe already has the Altiris Quarantine solution deployed for...

Configuring Qualys Guard to Send Events to CSMARS

Qualys provides network security audits and vulnerability assessments of your network using the QualysGuard solution. When used with the NAC Framework, QualysGuard can receive messages from ACS to scan nonresponsive hosts to assist in determining their system posture token. If you have a subscription with QualysGuard, you can configure CS-MARS to connect to the QualysGuard API server and retrieve the vulnerability analysis reports. These reports are then parsed and inserted into the CS-MARS...

Step 3 Address Assignment

After a successful user authentication, the VPN client requests an IP address to be assigned to the VPN adapter on the workstation. The VPN client uses this address to source the clear-text traffic to be sent over the tunnel. For a Cisco VPN client, this address is assigned to the IPSec VPN adapter, while for the L2TP over IPSec client, this IP address is assigned to the L2TP VPN adapter. The Cisco VPN 3000 concentrator supports four different methods to assign an IP address to the client Use...

Radius Authorization Components

RADIUS authorization components, or RACs, as they are more commonly referred to, are groupings of RADIUS attributes that map back to a NAC policy and are applied to a NAD during the posture-enforcement phase. These attributes apply NAC timers, assign ports to the specified VLAN, enforce policy-based ACLs, and apply URL redirect ACLs. Table 8-5 lists the NAC method along with the mandatory RADIUS attributes on the right. Table 8-5 RADIUS Attributes Used in NAC RADIUS Authorization Components...

Architectural Overview of NAC on Layer 3 Devices

The posture-validation process on a Layer 3 device starts when an end host requests access to the network. Figure 5-1 provides a complete flow of the posture-validation process on a Layer 3 NAD. A Cisco 3845 router is acting as the Layer 3 NAD to validate the end host's posture before allowing access to the corporate network. This assessment is checked against the policies defined on the Cisco Secure Access Control Server (Cisco Secure ACS). Figure 5-1 Layer 3 Posture-Validation Process for a...

Centralized Agentless Host Policy for NACL28021X MAC Authentication Bypass

Similar to the agentless host policy for NAC-L3-IP and NAC-L2-IP, ACS provides a NAC template to authenticate and authorize those agentless hosts in NAC-L2-802.1X-enabled networks. The NAC template used for this is titled Agentless Host for L2 (802.1X fallback). The NAC-L2-802.1X Agentless Host Policy enables you to configure exceptions, based on MAC addresses, for hosts without the NAC-enabled 802.1X supplicant to connect to the network. The exceptions authenticate the hosts based on MAC...

Architectural Overview of NAC for Agentless Hosts

The posture-validation process is crucial in determining the correct status of a network device. When CTA is not present on a device, the NAD can leverage an audit server when an end machine requests access to the network. Figure 11-2 provides a complete flow of the posture-validation process on a Cisco NAD. A Cisco switch is set up for NAC-L2-IP to validate an end host's posture before allowing access to the corporate network. Figure 11-2 Posture-Validation Process for a Host Figure 11-2...

Posture Validation Policy

On the Posture Validation Policy page, contained within the NAP, you create posture-validation rules. Each rule comprises a condition and actions. If the condition is met, the actions are applied. Therefore, the condition can also be seen as a filter applied to the posture-validation policy. The condition is defined as the set of required credential types. Said another way, the condition is met if the posture credentials received in the RADIUS request match all the selected credentials in the...

Monitoring of NAC Sessions

Show Vpn Sessiondb Summary

You can use several show commands to monitor and report the state of NAC sessions. The show vpn-sessiondb remote command is one of the most commonly used because it displays IPSec as well as NAC statistics of all the VPN clients. As shown in Example 7-41, the session type is remote for remote-access tunnel, and the VPN username is ciscouser. The assigned IP address is 10.10.200.1 and the public IP address is 209.165.202.159. The security appliance has transmitted 15,790 bytes and has received...

Diagnosing NAC on Catalyst 6500 Switch

Show commands are very useful in determining the current state and posture of an end host. However, they do not provide a historical reference of how (or why) the host ended up there. In the Catalyst 6500 switch running CAT OS, you can verify the NAC Layer 2 IP functionality and posture using the show policy group all command. It shows you the configured NAC group name and the hosts that are bound to each group. In Example 14-1, a Healthy group name is displayed the associated IP address is...