06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Using Profile Templates<br />

Table 14-9 Authorization Rules <strong>for</strong> NAC Layer 2 801.x Profile Sample (continued)<br />

Authorization Rules <strong>User</strong> group<br />

Include RADIUS attributes<br />

from user's group<br />

Include RADIUS attributes<br />

from user record<br />

Microsoft IEEE 802.1x<br />

14-16<br />

Unchecked<br />

Unchecked<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

System Posture<br />

Token RAC DACL<br />

Chapter 14 Network <strong>Access</strong> Profiles<br />

Table 14-10 describes the content of the posture-validation policies in the NAC Layer 802.1x Sample<br />

Profile Template.<br />

Table 14-10 Posture Validation <strong>for</strong> NAC Layer 2 802.1x Profile Sample<br />

Section Object Value<br />

Internal<br />

posture policy<br />

NAC-SAMPLE-CTA-POLICY Condition System Posture Token Notification String<br />

Rule 1 <strong>Cisco</strong>:PA:PA-Nam<br />

e contains CTA<br />

and <strong>Cisco</strong>:PA:PA-<br />

Version >=1.0<br />

<strong>Cisco</strong>:PA:Healthy N/A<br />

Default N/A <strong>Cisco</strong>:PA:Quarantine N/A<br />

Table 14-11 describes the content of the Shared Profile Components in the NAC Layer 802.1x Sample<br />

Profile Template.<br />

Table 14-11 Shared Profile Components <strong>for</strong> NAC Layer 2 802.1x Profile Template<br />

Type Object Value<br />

RADIUS<br />

Authorization<br />

Components<br />

NAC-SAMPLE-HEALTHY-L2-R<br />

AC<br />

NAC-SAMPLE-<br />

QUARANTINE-L2-RAC<br />

[027] Session-Timeout = 36,000<br />

[26/9/1] cisco-av-pair sec:pg=healthy_hosts<br />

[029] Termination-Action RADIUS-Request (1)<br />

[064] Tunnel-Type [T1] VLAN (13)<br />

[065] Tunnel-Medium-Type [T1] 802 (6)<br />

[081] Tunnel-Private-Group-ID = healthy<br />

[027] Session-Timeout = 3,600<br />

[26/9/1]cisco-av-pair sec:pg=quarantine_hosts<br />

[029] Termination-Action RADIUS-Request (1)<br />

[064] Tunnel-Type [T1] VLAN (13)<br />

[065] Tunnel-Medium-Type [T1] 802 (6)<br />

[081] Tunnel-Private-Group-ID = quarantine<br />

Be<strong>for</strong>e you use this template, ensure that you have checked the Allow EAP-MS-CHAPv2 option in the<br />

Global Authentication Setup page.<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!