HP 3350 - Cisco NAC Appliance Spezifikationen Seite 221

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 220
6-7
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 6 User Management: Configuring User Roles and Local Users
Create User Roles
Default Login Page
A default login page must be added and present in the system in order for both the web login and Agent
users to authenticate.
The login page is generated by Cisco NAC Appliance and is shown to end users by role. When users first
try to access the network from a web browser, an HTML login page appears prompting the users for a
user name and password. Cisco NAC Appliance submits these credentials to the selected authentication
provider and uses them determine the role in which to put the user. You can customize this web login
page to target the page to particular users based on a user’s VLAN ID, subnet, and operating system.
Caution If a default login page is not present, Agent users will see an error dialog when attempting login (“Clean
Access Server is not properly configured, please report to your administrator.”).
Note For L3 OOB deployments, you must also Enable Web Client for Login Page, page 5-5.
For details on creating and configuring the web user login page, see Chapter 5, “Configuring User Login
Page and Guest Access. To quickly add a default login page, see Add Default Login Page, page 5-3.
Traffic Policies for Roles
When you first create a role, it has a default traffic filtering policy of “deny all” for traffic moving from
the untrusted side to the trusted side, and “allow all” for traffic from the trusted side to the untrusted side.
Therefore, after creating the role, you need to create policies to permit the appropriate traffic. See
Chapter 8, “User Management: Traffic Control, Bandwidth, Schedule” for details on how to configure
IP-based and host-based traffic policies for user roles.
In addition, traffic policies need to be configured for the Agent Temporary role and the quarantine role
to prevent general access to the network but allow access to web resources or remediation sites necessary
for the user to meet requirements or fix vulnerabilities.See Configure Policies for Agent Temporary and
Quarantine Roles, page 8-19 for details.
Adding a New User Role
The Agent Temporary role and a Quarantine role already exist in the Cisco NAC Appliance system and
only need to be configured to meet your specific network needs. However, normal login roles (or any
additional quarantine roles) must first be added. Once a new role is created, it can then be associated to
the traffic policies and other properties you customize in the web console for your environment.
Note For new roles, traffic policies must be added to allow traffic from the untrusted to the trusted network.
See Chapter 8, “User Management: Traffic Control, Bandwidth, Schedule” for details.
Step 1 Go to User Management > User Roles > New Role (Figure 6-2).
Seitenansicht 220
1 2 ... 216 217 218 219 220 221 222 223 224 225 226 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare