22-35
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter22 Network Admission Control
How Do I...
The access rule must contain deny statements that specify the traffic that is to be
exempted from the admission control process. No posture validation triggering
occurs if the access rule contains only deny statements.
An example of ACL entries for a NAC admission rule follows:
deny udp any host 10.10.30.10 eq domain
deny tcp any host 10.10.20.10 eq www
permit ip any any
The first deny statement exempts traffic with a destination of port 53 (domain),
and the second statement exempts traffic with a destination of port 80(www). The
permit statement ending the ACL ensures that posture validation occurs.
How Do I...
The following topics contain procedures for performing tasks that the Cr eate NAC
wizard does help you to do.
How Do I Configure a NAC Policy Server?
The router must have a connection to a Cisco Secure Access Control Server (ACS)
version 3.3, configured to use the RADIUS protocol, in order to implement NAC.
The document at the following link contains an overview of the configuration
process.
http://www.cisco.com/application/pdf/en/us/guest/netsol/ns466/c654/cdccont
_0900aecd80217e26.pdf
Documents at the following link explain how to install and configure Cisco Secure
ACS for Windows Servers version 3.3.
http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/a
cs33/index.htm
How Do Install and Configure a Posture Agent on a Host?
If you are a registered Cisco.com user, you can download Cisco Trust Agent
(CTA) software from the following link: