HP 3350 - Cisco NAC Appliance Spezifikationen Seite 489

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 488
11-10
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 11 Monitoring and Troubleshooting Agent Sessions
Manage Certified Devices
Manage Certified Devices
This section describes the following:
Add Exempt Device, page 11-12
Clear Certified or Exempt Devices Manually, page 11-13
View Reports for Certified Devices, page 11-13
View Switch/WLC Information for Out-of-Band Certified Devices, page 11-13
Configure Certified Device Timer, page 11-14
Add Floating Devices, page 11-16
The Clean Access Manager web console provides two important lists that manage users and their
devices: the Online Users list (both In-Band and Out-of-Band) and Certified Devices List. The Online
Users list displays logged-in users by IP address and login credentials (see Interpreting Event Logs,
page 13-4). When a user device passes network scanning or meets Agent Requirements, the Clean
Access Server automatically adds the MAC address of the device to the Certified Devices List (for users
with Layer 2 proximity to the CAS).
Note Because the Certified Devices List is based on client MAC addresses, the Certified Devices List never
applies to users in Layer 3 deployments. Web login users that are one or more Layer 3 hops away from
the CAS are tracked by IP address only, unless the ActiveX/Java applet web client is enabled for the login
page (to obtain the MAC address of the client). For further details on Layer 3 deployment, see “Enable
L3 Deployment Support” in the Cisco NAC Appliance - Clean Access Server Configuration Guide,
Release 4.9(x).
Dropping an In-Band user from the In-Band Online Users list does not remove the client device from the
Certified Devices List. However, manually dropping an In-Band client from the Certified Devices List
automatically removes the user from the network and the In-Band Online Users list.
Dropping an Out-of-Band user from the Out-of-Band Online Users list has different results depending
on your Cisco NAC Appliance configuration:
In a deployment where Out-of-Band Logoff has been enabled, the client machine is also
automatically removed from the Certified Devices List.
If Out-of-Band Logoff is not enabled and you kick the user from the Out-of-Band Online Users list,
the client machine stays in the Certified Devices List just as with an In-Band deployment.
For more information on Out-of-Band logoff, see Configure Out-of-Band Logoff, page 9-6.
For network scanning, once on the Certified Devices List, the device does not have to be recertified as
long as its MAC address is in the Certified Devices List, even if the user of the device logs out and
accesses the network again as another user. Dropping a client from the Certified Devices List forces the
user to repeat authentication and the device to repeat network scanning to be readmitted to the network.
(Multi-user devices should be configured as floating devices to require recertification at each login.) You
can make sure that a device is always removed from the Certified Devices List when a network scanning
user logs off by enabling the option Require users to be certified at every web login in the General
Setup > Web Login tab (see Client Login Overview, page 1-6.)
For Agent users, devices always go through Agent Requirements at each login, even if the device is
already on the Certified Devices List. In addition, the Certified Devices List only records the first user
that logged in with the device. This helps to identify the authenticating user who accepted the User
Seitenansicht 488
1 2 ... 484 485 486 487 488 489 490 491 492 493 494 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare