HP 3350 - Cisco NAC Appliance Spezifikationen Seite 315

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 314
9-9
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 9 Configuring Cisco NAC Appliance for Agent Login and Client Posture Assessment
Require Agent Login for Client Machines
Block discovery packets from all non-NAC networks to the CAS untrusted interface IP address
(discovery packets that arrive on the trusted interface of the CAS are blocked by default)
Note These scenarios are not specific to OOB logoff feature and represent general Cisco NAC Agent behavior
for some Out-of-Band topologies.
Enable Out-of-Band Logoff
The following steps explain how to enable Out-of-Band Logoff for the NAC and Mac OS X Agents.
Step 1 Go to Device Management > Clean Access > General Setup > Agent Login (Figure 9-1).
Step 2 Check the Enable OOB logoff for Windows NAC Agent and Mac OS X Agent checkbox. Once
enabled, this setting applies to all Out-of-Band CASs managed by this CAM in the Cisco NAC Appliance
deployment, applies to all the user roles, and applies to all client machines logging in via the Cisco NAC
Agent and Mac OS X Agent, regardless of other settings in assigned user roles.
Step 3 Click Update and confirm the requirement to reboot all Out-of-Band CASs associated with this CAM
by clicking OK in the dialog box that appears (Figure 9-4). After you enable the Out-of-Band logoff
feature, full Out-of-Band Logoff functions are not available to Agents logging into the network until you
reboot the Out-of-Band CAS. In addition, if you enable Out-of-Band Logoff on one CAS in an HA
deployment, you must reboot the CAS-pair if they are already managed by CAM. See Reboot the Clean
Access Server, page 2-8.
Figure 9-4 Enable OOB Logoff—Acknowledge Requirement to Reboot CASs
Tip To verify whether or not the Out-of-Band Logoff feature is enabled on a particular Out-of-Band CAS,
log in to the CAS CLI and enter the netstat -unl | egrep -w '890[12]' commands to see if the required
ports are open. If so, the CAS should return the following:
[root@CAS1]# netstat -unl | egrep -w '890[12]'
udp 0 0 10.0.0.100:8901 0.0.0.0:*
udp 0 0 10.0.0.100:8902 0.0.0.0:*
This can be a very useful tool to help quickly determine which Out-of-Band CASs in a multiple-CAS
environment do and do not currently have the Out-of-Band Logoff feature enabled.
Troubleshooting OOB Logoff
If you have problems with the OOB Logoff feature, check the following:
Seitenansicht 314
1 2 ... 310 311 312 313 314 315 316 317 318 319 320 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare