22-25
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter22 Network Admission Control
Create NAC Tab

Add, Edit, and Ping Buttons

To provide information for a RADIUS server, click the Add button and enter the
information in the screen displayed. Select a row and click Edit to modify the
information for a RADIUS server. Select a row and click Ping to test the
connection between the router and a RADIUS server.
The Add The Edit and the Ping buttons are disabled when no RADIUS server
information is available for the selected interface.
Select the Interface(s)
Select the interfaces on which to enable NAC in this window. Select the interfaces
through which network hosts connect to the network. A default NAC policy is
applied to the interfaces that you select. This NAC policy can be edited after you
complete the initial configuration.
A default NAC policy is applied to the interfaces that you select. The default
policy does not exempt any traffic from the posture validation process. After you
complete the wizard, you can modify the policy by associating an access rule,
called an admissions rule, with the NAC policy. The admissions rule can specify
the types of traffic that are to be exempted from posture validation

Interfaces Check Boxes

Check the box next to each interface on which you want to enable NAC. Interfaces
with an existing NAC policy do not appear in this list, and interfaces configured
as RADIUS source interfaces do not appear in this list.
NAC Exception List
You can identify hosts that must be allowed to bypass the NAC validation process
in this screen. Typically, hosts such as printers, IP phones, and hosts without NAC
posture agent software installed are added to the exception list. Hosts without
static addresses cannot be entered in this list.
If you do not need to configure a NAC exception list, you can click Next without
entering information in this window. As an alternative or as a complement to the
NAC exception list, this wizard allows you to configure a agentless host policy in
another window.