06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14 Network <strong>Access</strong> Profiles<br />

Create Profile from Template Page<br />

OL-14386-02<br />

Network <strong>Access</strong> Profiles Pages Reference<br />

Use to this page to create a new profile from a template.<br />

To open this page, choose Network <strong>Access</strong> Profiles > Add Profile from Template.<br />

Table 14-22 Create Profile from Template Page<br />

Option Description<br />

Name A name <strong>for</strong> the profile.<br />

Description A description <strong>for</strong> the profile.<br />

Template The list of available templates.<br />

Note The NAC L3 IP template requires the Allow Posture Validation<br />

setting on the Protocols Settings <strong>for</strong> profile_name Page.<br />

Active Activates or deactivates the profile.<br />

Submit Submits modifications. Returns to the Profile Setup Page.<br />

Cancel Returns to the Profile Setup Page without implementing changes.<br />

Related Topics<br />

Using Profile Templates, page 14-7<br />

Protocols Settings <strong>for</strong> profile_name Page<br />

Use this page to set password protocols and EAP configuration.<br />

To open this page, choose Network <strong>Access</strong> Profiles > Protocols (appears <strong>for</strong> each profile).<br />

Table 14-23 Protocols and EAP Configuration Page<br />

Option Description<br />

Populate from Global Populates the Protocol Settings with the ACS Global Authentication settings.<br />

This method facilitates configuration of the authentication settings <strong>for</strong> new<br />

profiles.<br />

Authentication Protocols<br />

Allow PAP Enables PAP. PAP uses clear-text passwords (that is, unencrypted passwords) and<br />

is the least secure authentication protocol.<br />

Allow CHAP Enables CHAP. CHAP uses a challenge-response mechanism with password<br />

encryption. CHAP does not work with the Windows user database.<br />

Allow MS-CHAPv1 Enables MS-CHAPv1.<br />

Allow MS-CHAPv2 Enables MS-CHAPv2.<br />

Allow Agentless Request Processing Enable to configure the authentication process <strong>for</strong> a profile that receives a MAC<br />

address request.<br />

EAP Configuration<br />

Allow RADIUS Key Wrap Enables RADIUS Key Wrap attributes in PEAP, EAP-FAST and EAP-TLS<br />

authentication.<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

14-43

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!