30-11
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Chapter30 Network Admission Control
Create NAC Tab
Cisco SDM traffic from hosts on that network. The host or network must be
accessible from the interfaces that you specified. Choose Any to allow Cisco
SDM traffic from any host connected to the specified interfaces.
Modify Firewall
Cisco SDM checks each ACL applied to the interface specified in this
configuration to determine if it blocks any traffic that should be allowed thro ugh
the firewall so that the feature you are configuring will work.
Each interface is listed, along with the service currently being blocked on that
interface, and the ACL that is blocking it. If you want Cisco SDM to modify the
ACL to allow the traffic listed, check the Modify box in the appropriate row. If
you want to see the entry that Cisco SDM will add to the ACL, click the Details
button.
In the following table, FastEthernet0/0 has been configured for NAC. This
interface is configured with the services shown in the Service column.

Details Window

This window displays the entries that Cisco SDM will add to ACLs to allow
services needed for the service you are configuring. The window might contain an
entry like the following:
permit tcp host 10.77.158.84 eq www host 10.77.158.1 gt 1024
In this case, web traffic whose port number is greater than 1024 is permitted from
the host 10.77.158.84 on the local network to the host 10.77.158.1
Interface Service ACL Action
FastEthernet0/0 RADIUS Server 101 (INBOUND) [ ] Modify
FastEthernet0/0 DNS 100 (INBOUND) [ ] Modify
FastEthernet0/0 DHCP 100 (INBOUND) [ ] Modify
FastEthernet0/0 NTP 101 (INBOUND) [ ] Modify
FastEthernet0/0 VPN 190 (INBOUND) [ ] M odify