30-5
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Chapter30 Network Admission Control
Create NAC Tab
If you choose Router chooses source, the source IP address in the RADIUS
packets will be the address of the interface through which the RADIUS packets
exit the router.
If you choose an interface, the source IP address in the RADIUS packets will be
the address of the interface that you chose as the RADIU S client source.
Note Cisco IOS software allows a single RADIUS source interface to be configured on
the router. If the router already has a configured RADIUS source and you choose
a different source, the source IP address plac ed in the packets sent to the RA DIUS
server changes to the IP address of the new source, and may not match the NAD
IP address configured on the Cisco ACS.
Details Button
If you need a quick snapshot of the information about an interface before choosing
it, click Details. The screen shows you the IP address and subnet mask, the access
rules and inspection rules applied to the interface, the IPSec policy and QoS
policy applied, and whether there is an Easy VPN configuration on the interface.
Server IP, Timeout, and Parameters Columns
The Server IP, Timeout, and Parameters columns contain the information that the
router uses to contact a RADIUS server. If no RADIUS server information is
associated with the chosen interface, these columns are blank.
Use for NAC Check Box
Check this box if you want to use the listed RADIUS server for NAC. The server
must have the required admissions control policies configured if NAC is to be able
to use the server.
Add, Edit, and Ping Buttons
To provide information for a RADIUS server, click the Add button and enter the
information in the screen displayed. Choose a row and click Edit to modify the
information for a RADIUS server. Choose a row and click Ping to test the
connection between the router and a RADIUS server.