12.07.2015 Views

Bypassing NAC v2.0 - OSSIR

Bypassing NAC v2.0 - OSSIR

Bypassing NAC v2.0 - OSSIR

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Architecture• Components– Cisco Trust Agent (CTA)– Cisco network access device (NAD) with <strong>NAC</strong> enabled on one ormore interfaces for network access enforcement– Cisco Secure Access Control Server (ACS) for endpointcompliance validation• Enforcement strategies– <strong>NAC</strong> L3 IP• Deployed using Routers• Triggered by an IP packet– <strong>NAC</strong> L2 IP• Deployed using switches/routers• Apply per interface• Triggered by either a DHCP packet or an ARP request– <strong>NAC</strong> L2 802.1x• Triggered by any data-link packet

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!