06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 14 Network <strong>Access</strong> Profiles<br />

OL-14386-02<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Using Profile Templates<br />

Note Do not use the Populate from Global button; otherwise, this authentication field will be inherited from<br />

the settings in the Global Authentication Setup in System Configuration.<br />

Table 14-5 describes the content of the Profile in the NAC Layer 2 IP Sample Profile Template.<br />

Table 14-5 NAC Layer 2 IP Profile Sample<br />

Section Property Value<br />

NAP Name <strong>User</strong> configurable<br />

Description <strong>User</strong> configurable<br />

Profile NAF N/A<br />

Protocol N/A<br />

Advance filter ([[26/9/1]<strong>Cisco</strong> av-pair]aaa:service = ip_admission)<br />

AND ([006]Service-Type != 10)<br />

Authentication PEAP Allow Posture Only is checked<br />

Credential Validation Database N/A<br />

Posture Validation Posture Name NAC-EXAMPLE-POSTURE-EXAMPLE<br />

Validation<br />

Rule<br />

Required credential<br />

types<br />

<strong>Cisco</strong>:PA<br />

Selected internal<br />

posture policies<br />

NAC-SAMPLE-CTA-POLICY<br />

Selected external<br />

posture policies<br />

N/A<br />

System Posture System Posture PA message URL Redirect<br />

Token configuration Token<br />

Healthy Healthy N/A<br />

Checkup Checkup N/A<br />

Transition Transition N/A<br />

Quarantine Quarantine N/A<br />

Infected Infected N/A<br />

Unknown Unknown N/A<br />

Table 14-6 describes the content of the Authorization Rules in the NAC Layer 2 IP Sample Profile<br />

Template.<br />

Table 14-6 Authorization Rules <strong>for</strong> NAC Layer 2 IP Profile Template<br />

Authorization Rules <strong>User</strong>-Group<br />

System Posture<br />

Token RAC DACL<br />

Rule 1 N/A Healthy NAC-SAMPLE-<br />

HEALTHY-L3-RAC<br />

Rule 2 N/A Quarantine NAC-SAMPLE-<br />

QUARANTINE-L3-RAC<br />

NAC-SAMPLE-<br />

HEALTHY-ACL<br />

NAC-SAMPLE-<br />

QUARANTINE-ACL<br />

14-13

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!